Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3604
HistoryOct 21, 2009 - 12:00 a.m.

CVE-2009-3604

2009-10-2100:00:00
ubuntu.com
ubuntu.com
14

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.418

Percentile

97.3%

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before
3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not
properly allocate memory, which allows remote attackers to cause a denial
of service (application crash) or possibly execute arbitrary code via a
crafted PDF document that triggers a NULL pointer dereference or a
heap-based buffer overflow.

Rows per page:
1-10 of 411

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.418

Percentile

97.3%