Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade poppler-utilsUpgrade poppler-develUpgrade poppler | Dec 1, 2016 | Oct 21, 2009 |
| Debian | — | Upgrade popplerUpgrade xpdf | Jul 30, 2024 | Oct 21, 2009 |
| Gentoo Linux | — | Upgrade app-text/poppler. | Oct 30, 2017 | Oct 21, 2009 |
| Oracle_linux | — | Upgrade poppler-develUpgrade popplerUpgrade poppler-utils | Oct 16, 2024 | Oct 21, 2009 |
| Suse | — | Upgrade xpdf-toolsUpgrade xpdf | Feb 17, 2015 | Oct 21, 2009 |
| Ubuntu | — | Upgrade libpoppler1-glibUpgrade libpoppler4Upgrade libpoppler-glib3Upgrade libpoppler3Upgrade libpoppler5Upgrade libpoppler2Upgrade libpoppler-glib2Upgrade libpoppler-glib4Upgrade libpoppler1 | Nov 8, 2024 | Oct 21, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub