Lucene search

K
cveMitreCVE-2009-0756
HistoryMar 03, 2009 - 4:30 p.m.

CVE-2009-0756

2009-03-0316:30:05
mitre
web.nvd.nist.gov
35
cve-2009-0756
jbig2stream
poppler
denial of service
crash
pdf
parsing error
remote attackers
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.057

Percentile

93.4%

The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.

Affected configurations

Nvd
Node
popplerpopplerRange0.10.3
OR
popplerpopplerMatch0.1
OR
popplerpopplerMatch0.1.1
OR
popplerpopplerMatch0.1.2
OR
popplerpopplerMatch0.2.0
OR
popplerpopplerMatch0.3.0
OR
popplerpopplerMatch0.3.1
OR
popplerpopplerMatch0.3.2
OR
popplerpopplerMatch0.3.3
OR
popplerpopplerMatch0.4.0
OR
popplerpopplerMatch0.4.1
OR
popplerpopplerMatch0.4.2
OR
popplerpopplerMatch0.4.3
OR
popplerpopplerMatch0.4.4
OR
popplerpopplerMatch0.5.0
OR
popplerpopplerMatch0.5.1
OR
popplerpopplerMatch0.5.2
OR
popplerpopplerMatch0.5.3
OR
popplerpopplerMatch0.5.4
OR
popplerpopplerMatch0.5.9
OR
popplerpopplerMatch0.5.90
OR
popplerpopplerMatch0.5.91
OR
popplerpopplerMatch0.6.0
OR
popplerpopplerMatch0.6.1
OR
popplerpopplerMatch0.6.2
OR
popplerpopplerMatch0.6.3
OR
popplerpopplerMatch0.6.4
OR
popplerpopplerMatch0.7.0
OR
popplerpopplerMatch0.7.1
OR
popplerpopplerMatch0.7.2
OR
popplerpopplerMatch0.7.3
OR
popplerpopplerMatch0.8.4
OR
popplerpopplerMatch0.10.1
OR
popplerpopplerMatch0.10.2
VendorProductVersionCPE
popplerpoppler0.3.0cpe:/a:poppler:poppler:0.3.0:::
popplerpoppler0.5.90cpe:/a:poppler:poppler:0.5.90:::
popplerpoppler0.7.3cpe:/a:poppler:poppler:0.7.3:::
popplerpoppler0.8.4cpe:/a:poppler:poppler:0.8.4:::
popplerpoppler0.6.1cpe:/a:poppler:poppler:0.6.1:::
popplerpoppler0.3.3cpe:/a:poppler:poppler:0.3.3:::
popplerpoppler0.6.0cpe:/a:poppler:poppler:0.6.0:::
popplerpoppler0.4.3cpe:/a:poppler:poppler:0.4.3:::
popplerpoppler0.5.4cpe:/a:poppler:poppler:0.5.4:::
popplerpoppler0.4.1cpe:/a:poppler:poppler:0.4.1:::
Rows per page:
1-10 of 341

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.057

Percentile

93.4%