Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade poppler | Jul 30, 2024 | Nov 2, 2009 |
| Gentoo Linux | — | Upgrade app-text/poppler. | Oct 30, 2017 | Nov 2, 2009 |
| Suse | — | Upgrade xpdfUpgrade xpdf-tools | Feb 17, 2015 | Nov 2, 2009 |
| Ubuntu | — | Upgrade libpoppler2Upgrade libpoppler1Upgrade libpoppler-glib3Upgrade libpoppler3Upgrade libpoppler1-glibUpgrade libpoppler-glib2Upgrade libpoppler-glib4Upgrade libpoppler4 | Nov 8, 2024 | Nov 2, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub