Vulnerability Description
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foolabs | Xpdf | 0.5a |
| Glyphandcog | Xpdfreader | <= 3.02 |
| Apple | Cups | <= 1.3.9 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=263028
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
- http://rhn.redhat.com/errata/RHSA-2009-0458.html
- http://secunia.com/advisories/34291Vendor Advisory
- http://secunia.com/advisories/34481Vendor Advisory
- http://secunia.com/advisories/34755Vendor Advisory
- http://secunia.com/advisories/34756
- http://secunia.com/advisories/34852Vendor Advisory
- http://secunia.com/advisories/34959Vendor Advisory
- http://secunia.com/advisories/34963
- http://secunia.com/advisories/34991Vendor Advisory
FAQ
What is CVE-2009-0146?
CVE-2009-0146 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF fil...
How severe is CVE-2009-0146?
CVE-2009-0146 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0146?
Check the references section above for vendor advisories and patch information. Affected products include: Foolabs Xpdf, Glyphandcog Xpdfreader, Apple Cups.