PDF JBIG2 integer overflow
Published Apr 23, 2009
6.8
MEDIUMCVSS 2.0
EPSS 5.55%
Description
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.
Affected products
No data.
Configuration 1
- 0.5a
- 0.7a
- 0.91a
- 0.91b
- 0.91c
- 0.92a
- 0.92b
- 0.92c
- 0.92d
- 0.92e
- 0.93a
- 0.93b
- 0.93c
- 1.00a
- ≤ 3.02
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.7
- 0.80
- 0.90
- 0.91
- 0.92
- 0.93
- 1.00
- 1.01
- 2.00
- 2.01
- 2.02
- 2.03
- 3.00
- 3.01
Configuration 2
- ≤ 0.10.5
- 0.1
- 0.1.1
- 0.1.2
- 0.2.0
- 0.3.0
- 0.3.1
- 0.3.2
- 0.3.3
- 0.4.0
- 0.4.1
- 0.4.2
- 0.4.3
- 0.4.4
- 0.5.0
- 0.5.1
- 0.5.2
- 0.5.3
- 0.5.4
- 0.5.9
- 0.5.90
- 0.5.91
- 0.6.0
- 0.6.1
- 0.6.2
- 0.6.3
- 0.6.4
- 0.7.0
- 0.7.1
- 0.7.2
- 0.7.3
- 0.8.0
- 0.8.1
- 0.8.2
- 0.8.3
- 0.8.4
- 0.8.5
- 0.8.6
- 0.8.7
- 0.9.0
- 0.9.1
- 0.9.2
- 0.9.3
- 0.10.0
- 0.10.1
- 0.10.2
- 0.10.3
- 0.10.4
Configuration 3
- ≤ 1.3.9
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.5-1
- 1.1.5-2
- 1.1.6
- 1.1.6-1
- 1.1.6-2
- 1.1.6-3
- 1.1.7
- 1.1.8
- 1.1.9
- 1.1.9-1
- 1.1.10
- 1.1.10-1
- 1.1.11
- 1.1.12
- 1.1.13
- 1.1.14
- 1.1.15
- 1.1.16
- 1.1.17
- 1.1.18
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.19
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.20
- 1.1.21
- 1.1.21
- 1.1.21
- 1.1.22
- 1.1.22
- 1.1.22
- 1.1.23
- 1.1.23
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.2.10
- 1.2.11
- 1.2.12
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.10
- 1.3.11
No data.
Red Hat Enterprise Linux 3
xpdf-1:2.02-14.el3
Fixed · RHSA-2009:0430
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.27.el4_7.5
Fixed · RHSA-2009:0429
Red Hat Enterprise Linux 4
gpdf-0:2.8.2-7.7.2.el4_7.4
Fixed · RHSA-2009:0458
Red Hat Enterprise Linux 4
kdegraphics-7:3.3.1-13.el4
Fixed · RHSA-2009:0431
Red Hat Enterprise Linux 4
tetex-0:2.0.2-22.0.1.EL4.16
Fixed · RHSA-2010:0399
Red Hat Enterprise Linux 4
xpdf-1:3.00-20.el4
Fixed · RHSA-2009:0430
Red Hat Enterprise Linux 5
cups-1:1.3.7-8.el5_3.4
Fixed · RHSA-2009:0429
Red Hat Enterprise Linux 5
kdegraphics-7:3.5.4-12.el5_3
Fixed · RHSA-2009:0431
Red Hat Enterprise Linux 5
poppler-0:0.5.4-4.4.el5_3.9
Fixed · RHSA-2009:0480
Red Hat Enterprise Linux 5
tetex-0:3.0-33.8.el5_5.5
Fixed · RHSA-2010:0400
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | xpdf-1:2.02-14.el3 | Fixed | RHSA-2009:0430 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.27.el4_7.5 | Fixed | RHSA-2009:0429 |
| Red Hat Enterprise Linux 4 | gpdf-0:2.8.2-7.7.2.el4_7.4 | Fixed | RHSA-2009:0458 |
| Red Hat Enterprise Linux 4 | kdegraphics-7:3.3.1-13.el4 | Fixed | RHSA-2009:0431 |
| Red Hat Enterprise Linux 4 | tetex-0:2.0.2-22.0.1.EL4.16 | Fixed | RHSA-2010:0399 |
| Red Hat Enterprise Linux 4 | xpdf-1:3.00-20.el4 | Fixed | RHSA-2009:0430 |
| Red Hat Enterprise Linux 5 | cups-1:1.3.7-8.el5_3.4 | Fixed | RHSA-2009:0429 |
| Red Hat Enterprise Linux 5 | kdegraphics-7:3.5.4-12.el5_3 | Fixed | RHSA-2009:0431 |
| Red Hat Enterprise Linux 5 | poppler-0:0.5.4-4.4.el5_3.9 | Fixed | RHSA-2009:0480 |
| Red Hat Enterprise Linux 5 | tetex-0:3.0-33.8.el5_5.5 | Fixed | RHSA-2010:0400 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (53)
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html vendor-advisoryx_refsource_SUSE
- http://poppler.freedesktop.org/releases.html x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2009-0458.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/34291 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34481 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34746 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34755 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34756 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34852 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34959 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34963 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34991 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35037 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35064 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35065 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35379 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35618 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35685 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477 vendor-advisoryx_refsource_SLACKWARE
- http://support.apple.com/kb/HT3613 x_refsource_CONFIRM
- http://support.apple.com/kb/HT3639 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1790 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1793 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/196617 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:101 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:087 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:175 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2009-0429.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-0430.html vendor-advisoryx_refsource_REDHATPatch
- http://www.redhat.com/support/errata/RHSA-2009-0431.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2009-0480.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/34568 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022073 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2009/1065 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1066 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1076 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1077 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1522 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1621 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/1040 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1179 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=495889 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1179 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1179
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11892 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-1179
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.