Lucene search

K
freebsdFreeBSDA21037D5-2C38-11DE-AB3B-0017A4CCCFC6
HistoryApr 16, 2009 - 12:00 a.m.

xpdf -- multiple vulnerabilities

2009-04-1600:00:00
vuxml.freebsd.org
31

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.214

Percentile

96.5%

Secunia reports:

Some vulnerabilities have been reported in Xpdf, which can be
exploited by malicious people to potentially compromise a user’s
system.
A boundary error exists when decoding JBIG2 symbol dictionary
segments. This can be exploited to cause a heap-based buffer
overflow and potentially execute arbitrary code.
Multiple integer overflows in the JBIG2 decoder can be
exploited to potentially execute arbitrary code.
Multiple boundary errors in the JBIG2 decoder can be
exploited to cause buffer overflows and potentially execute
arbitrary code.
Multiple errors in the JBIG2 decoder can be exploited can be
exploited to free arbitrary memory and potentially execute arbitrary
code.
Multiple unspecified input validation errors in the JBIG2 decoder can
be exploited to potentially execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchxpdf<Β 3.02_11UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.214

Percentile

96.5%