Vulnerability Description
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Poppler | Poppler | <= 0.10.5 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=263028#c16Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.h
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.h
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.h
- http://poppler.freedesktop.org/releases.html
- http://secunia.com/advisories/34746
- http://secunia.com/advisories/35064
- http://secunia.com/advisories/35618
- http://secunia.com/advisories/37028
- http://secunia.com/advisories/37037
- http://secunia.com/advisories/37043
- http://secunia.com/advisories/37053
- http://secunia.com/advisories/37077
- http://secunia.com/advisories/37079
- http://secunia.com/advisories/39327
FAQ
What is CVE-2009-1188?
CVE-2009-1188 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF,...
How severe is CVE-2009-1188?
CVE-2009-1188 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1188?
Check the references section above for vendor advisories and patch information. Affected products include: Poppler Poppler.