Vulnerability CVE-2009-0799: Information

Description

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.

Severity: MEDIUM (4.3)

Published: April 23, 2009
Modified: March 6, 2019
Error type identifier: CWE-119

References to Advisories, Solutions, and Tools

Hyperlink
Resource
RHSA-2009:0430
  • Patch
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=495886
    34755
    • Vendor Advisory
    RHSA-2009:0431
    • Patch
    ADV-2009-1076
    • Patch
    • Vendor Advisory
    RHSA-2009:0429
    • Patch
    http://poppler.freedesktop.org/releases.html
    • Patch
    • Vendor Advisory
    ADV-2009-1066
    • Patch
    • Vendor Advisory
    34291
    • Vendor Advisory
    ADV-2009-1077
    • Vendor Advisory
    ADV-2009-1065
    • Patch
    • Vendor Advisory
    34481
    • Vendor Advisory
    34852
    • Vendor Advisory
    34568
    • Patch
    34746
    • Vendor Advisory
    1022072
      SUSE-SA:2009:024
        VU#196617
        • US Government Resource
        34756
        • Vendor Advisory
        MDVSA-2009:101
          34959
          • Vendor Advisory
          DSA-1790
          • Patch
          34963
          • Vendor Advisory
          RHSA-2009:0458
            35037
            • Vendor Advisory
            SSA:2009-129-01
              35065
              • Vendor Advisory
              SUSE-SR:2009:010
                RHSA-2009:0480
                • Patch
                34991
                • Vendor Advisory
                DSA-1793
                • Patch
                35064
                • Vendor Advisory
                SUSE-SR:2009:012
                  35618
                  • Vendor Advisory
                  FEDORA-2009-6973
                    FEDORA-2009-6982
                      35685
                      • Vendor Advisory
                      FEDORA-2009-6972
                        ADV-2010-1040
                        • Vendor Advisory
                        MDVSA-2010:087
                          MDVSA-2011:175
                            oval:org.mitre.oval:def:10204
                                1. Configuration 1

                                  cpe:2.3:a:foolabs:xpdf:0.91c:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.91b:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.93b:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:1.00a:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.91a:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.92e:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.5a:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.92b:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.93c:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.92c:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.7a:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.93a:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.92d:*:*:*:*:*:*:*

                                  cpe:2.3:a:foolabs:xpdf:0.92a:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.5:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.6:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.80:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.90:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:1.00:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:1.01:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:2.00:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:2.01:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:2.03:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:3.00:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:3.01:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.7:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.91:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.92:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:0.93:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:2.02:*:*:*:*:*:*:*

                                  cpe:2.3:a:glyphandcog:xpdfreader:*:*:*:*:*:*:*:*
                                  End including
                                  3.02

                                  Configuration 2

                                  cpe:2.3:a:poppler:poppler:0.7.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.3.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.10.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.4.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.5:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.9.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.10.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.10.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.7.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.6.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.3.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.91:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.6.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.3.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.4.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.10.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.9.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.6.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.1.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.7.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.7.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.6:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.9:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.90:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.6.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.2.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.1.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.9.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.4.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:*:*:*:*:*:*:*:*
                                  End including
                                  0.10.5

                                  cpe:2.3:a:poppler:poppler:0.4.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.7:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.9.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.3.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.6.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.10.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.4.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.5.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:poppler:poppler:0.8.2:*:*:*:*:*:*:*

                                  Configuration 3

                                  cpe:2.3:a:apple:cups:1.1.20:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.5-2:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.14:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.6-1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.18:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.12:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.11:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.5-1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.22:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.16:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.23:rc1:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.20:rc1:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.15:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.17:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.20:rc6:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.19:rc1:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.22:rc1:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.7:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.6-2:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.3:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.21:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.9:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.10:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.23:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.6:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.8:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.20:rc4:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.19:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.4:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.8:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.5:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.10:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.13:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.19:rc4:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.9-1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.12:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.21:rc2:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.7:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.6-3:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.20:rc5:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.9:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.7:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.19:rc5:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*
                                  End including
                                  1.3.9

                                  cpe:2.3:a:apple:cups:1.1.1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.8:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.2:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.10:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.11:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.22:rc2:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.21:rc1:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.11:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.19:rc3:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.6:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.10-1:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.0:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.5:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.3.6:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.20:rc2:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.20:rc3:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.2.5:*:*:*:*:*:*:*

                                  cpe:2.3:a:apple:cups:1.1.19:rc2:*:*:*:*:*:*