Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-0756
HistoryMar 03, 2009 - 12:00 a.m.

CVE-2009-0756

2009-03-0300:00:00
ubuntu.com
ubuntu.com
10

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.057

Percentile

93.4%

The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows
remote attackers to cause a denial of service (crash) via a PDF file that
triggers a parsing error, which is not properly handled by
JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory
dereference.

Bugs

Notes

Author Note
mdeslaur patch was replaced in a later fix (see second commit) later fix was in USN-759-1
OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchpoppler< 0.5.1-0ubuntu7.5UNKNOWN
ubuntu8.04noarchpoppler< 0.6.4-1ubuntu3.2UNKNOWN
ubuntu8.10noarchpoppler< 0.8.7-1ubuntu0.2UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.057

Percentile

93.4%