HIGH · 9.3

CVE-2009-3608

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow rem...

Vulnerability Description

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
FoolabsXpdf3.02pl1
GlyphandcogXpdfreader3.00
PopplerPoppler<= 0.12.0
Glyph And CogPdftopsAll versions
GnomeGpdfAll versions
KdeKpdfAll versions
TetexTetexAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-3608?

CVE-2009-3608 is a vulnerability with a CVSS score of 9.3 (HIGH). Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow rem...

How severe is CVE-2009-3608?

CVE-2009-3608 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-3608?

Check the references section above for vendor advisories and patch information. Affected products include: Foolabs Xpdf, Glyphandcog Xpdfreader, Poppler Poppler, Glyph And Cog Pdftops, Gnome Gpdf.