Lucene search

K
nvd[email protected]NVD:CVE-2009-3604
HistoryOct 21, 2009 - 5:30 p.m.

CVE-2009-3604

2009-10-2117:30:00
CWE-399
web.nvd.nist.gov
2

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.418

Percentile

97.3%

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.

Affected configurations

NVD
Node
gnomegpdf
OR
kdekpdf
AND
foolabsxpdfMatch3.02pl1
OR
foolabsxpdfMatch3.02pl2
OR
foolabsxpdfMatch3.02pl3
OR
glyphandcogxpdfreaderMatch2.00
OR
glyphandcogxpdfreaderMatch2.01
OR
glyphandcogxpdfreaderMatch2.02
OR
glyphandcogxpdfreaderMatch2.03
OR
glyphandcogxpdfreaderMatch3.00
OR
glyphandcogxpdfreaderMatch3.01
OR
glyphandcogxpdfreaderMatch3.02
OR
popplerpopplerMatch0.1
OR
popplerpopplerMatch0.1.1
OR
popplerpopplerMatch0.1.2
OR
popplerpopplerMatch0.2.0
OR
popplerpopplerMatch0.3.0
OR
popplerpopplerMatch0.3.1
OR
popplerpopplerMatch0.3.2
OR
popplerpopplerMatch0.3.3
OR
popplerpopplerMatch0.4.0
OR
popplerpopplerMatch0.4.1
OR
popplerpopplerMatch0.4.2
OR
popplerpopplerMatch0.4.3
OR
popplerpopplerMatch0.4.4
OR
popplerpopplerMatch0.5.0
OR
popplerpopplerMatch0.5.1
OR
popplerpopplerMatch0.5.2
OR
popplerpopplerMatch0.5.3
OR
popplerpopplerMatch0.5.4
OR
popplerpopplerMatch0.5.9
OR
popplerpopplerMatch0.5.90
OR
popplerpopplerMatch0.5.91
OR
popplerpopplerMatch0.6.0
OR
popplerpopplerMatch0.6.1
OR
popplerpopplerMatch0.6.2
OR
popplerpopplerMatch0.6.3
OR
popplerpopplerMatch0.6.4
OR
popplerpopplerMatch0.7.0
OR
popplerpopplerMatch0.7.1
OR
popplerpopplerMatch0.7.2
OR
popplerpopplerMatch0.7.3
OR
popplerpopplerMatch0.8.0
OR
popplerpopplerMatch0.8.1
OR
popplerpopplerMatch0.8.2
OR
popplerpopplerMatch0.8.3
OR
popplerpopplerMatch0.8.4
OR
popplerpopplerMatch0.8.5
OR
popplerpopplerMatch0.8.6
OR
popplerpopplerMatch0.8.7
OR
popplerpopplerMatch0.9.0
OR
popplerpopplerMatch0.9.1
OR
popplerpopplerMatch0.9.2
OR
popplerpopplerMatch0.9.3
OR
popplerpopplerMatch0.10.0
OR
popplerpopplerMatch0.10.1
OR
popplerpopplerMatch0.10.2
OR
popplerpopplerMatch0.10.3
OR
popplerpopplerMatch0.10.4
OR
popplerpopplerMatch0.10.5
OR
popplerpopplerMatch0.10.6
OR
popplerpopplerMatch0.10.7
OR
popplerpopplerMatch0.11.0
OR
popplerpopplerMatch0.11.1
OR
popplerpopplerMatch0.11.2
OR
popplerpopplerMatch0.11.3
OR
popplerpopplerMatch0.12.0

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.418

Percentile

97.3%