Lucene search

K
cveRedhatCVE-2009-3603
HistoryOct 21, 2009 - 5:30 p.m.

CVE-2009-3603

2009-10-2117:30:00
CWE-189
redhat
web.nvd.nist.gov
49
cve-2009-3603
integer overflow
xpdf
poppler
pdf
remote code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.206

Percentile

96.5%

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.

Affected configurations

Nvd
Node
foolabsxpdfMatch3.02pl1
OR
foolabsxpdfMatch3.02pl2
OR
foolabsxpdfMatch3.02pl3
OR
glyphandcogxpdfreaderMatch3.00
OR
glyphandcogxpdfreaderMatch3.01
OR
glyphandcogxpdfreaderMatch3.02
OR
popplerpopplerRange0.12.0
OR
popplerpopplerMatch0.1
OR
popplerpopplerMatch0.1.1
OR
popplerpopplerMatch0.1.2
OR
popplerpopplerMatch0.2.0
OR
popplerpopplerMatch0.3.0
OR
popplerpopplerMatch0.3.1
OR
popplerpopplerMatch0.3.2
OR
popplerpopplerMatch0.3.3
OR
popplerpopplerMatch0.4.0
OR
popplerpopplerMatch0.4.1
OR
popplerpopplerMatch0.4.2
OR
popplerpopplerMatch0.4.3
OR
popplerpopplerMatch0.4.4
OR
popplerpopplerMatch0.5.0
OR
popplerpopplerMatch0.5.1
OR
popplerpopplerMatch0.5.2
OR
popplerpopplerMatch0.5.3
OR
popplerpopplerMatch0.5.4
OR
popplerpopplerMatch0.5.9
OR
popplerpopplerMatch0.6.0
OR
popplerpopplerMatch0.6.1
OR
popplerpopplerMatch0.6.2
OR
popplerpopplerMatch0.6.3
OR
popplerpopplerMatch0.6.4
OR
popplerpopplerMatch0.7.0
OR
popplerpopplerMatch0.7.1
OR
popplerpopplerMatch0.7.2
OR
popplerpopplerMatch0.7.3
OR
popplerpopplerMatch0.8.0
OR
popplerpopplerMatch0.8.1
OR
popplerpopplerMatch0.8.2
OR
popplerpopplerMatch0.8.3
OR
popplerpopplerMatch0.8.4
OR
popplerpopplerMatch0.8.6
OR
popplerpopplerMatch0.8.7
OR
popplerpopplerMatch0.9.0
OR
popplerpopplerMatch0.9.1
OR
popplerpopplerMatch0.9.2
OR
popplerpopplerMatch0.9.3
OR
popplerpopplerMatch0.10.0
OR
popplerpopplerMatch0.10.1
OR
popplerpopplerMatch0.10.2
OR
popplerpopplerMatch0.10.3
OR
popplerpopplerMatch0.10.4
OR
popplerpopplerMatch0.10.5
OR
popplerpopplerMatch0.10.6
OR
popplerpopplerMatch0.10.7
OR
popplerpopplerMatch0.11.0
OR
popplerpopplerMatch0.11.1
OR
popplerpopplerMatch0.11.2
OR
popplerpopplerMatch0.11.3
VendorProductVersionCPE
foolabsxpdf3.02pl1cpe:2.3:a:foolabs:xpdf:3.02pl1:*:*:*:*:*:*:*
foolabsxpdf3.02pl2cpe:2.3:a:foolabs:xpdf:3.02pl2:*:*:*:*:*:*:*
foolabsxpdf3.02pl3cpe:2.3:a:foolabs:xpdf:3.02pl3:*:*:*:*:*:*:*
glyphandcogxpdfreader3.00cpe:2.3:a:glyphandcog:xpdfreader:3.00:*:*:*:*:*:*:*
glyphandcogxpdfreader3.01cpe:2.3:a:glyphandcog:xpdfreader:3.01:*:*:*:*:*:*:*
glyphandcogxpdfreader3.02cpe:2.3:a:glyphandcog:xpdfreader:3.02:*:*:*:*:*:*:*
popplerpoppler*cpe:2.3:a:poppler:poppler:*:*:*:*:*:*:*:*
popplerpoppler0.1cpe:2.3:a:poppler:poppler:0.1:*:*:*:*:*:*:*
popplerpoppler0.1.1cpe:2.3:a:poppler:poppler:0.1.1:*:*:*:*:*:*:*
popplerpoppler0.1.2cpe:2.3:a:poppler:poppler:0.1.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 581

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.206

Percentile

96.5%