Back to Database
Status published
Critical
CVE-2009-0165
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and...
Vulnerability Description
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0165
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2009/dsa-1793
- http://support.apple.com/kb/HT3639
- http://www.debian.org/security/2009/dsa-1790
- http://secunia.com/advisories/35037
- http://www.vupen.com/english/advisories/2009/1621
- http://support.apple.com/kb/HT3549
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477
- http://bugs.gentoo.org/show_bug.cgi?id=263028
- http://secunia.com/advisories/35074
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
- http://secunia.com/advisories/35065
- http://www.securityfocus.com/bid/34568
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
- http://secunia.com/advisories/34991
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:101
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html
- http://secunia.com/advisories/35685
- http://www.vupen.com/english/advisories/2009/1297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50377
- http://secunia.com/advisories/34852
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
- http://secunia.com/advisories/34959
More from foolabs
View All →CVE-2009-3609
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf...
Medium
4.3
CVE-2009-3608
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf...
Critical
9.3
CVE-2009-3606
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4,...
Critical
9.3
CVE-2009-3604
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x...
Critical
9.3
CVE-2009-3603
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before...
Critical
9.3
Affected Vendor
foolabs
View all reports →Affected Software
xpdf, xpdfreader
Vulnerable Versions:
0.5a, 0.7a, 0.91a, 0.91b, 0.91c, 0.92a, 0.92b, 0.92c, 0.92d, 0.92e, 0.93a, 0.93b, 0.93c, 1.00a, 3.0.1, 0, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.80, 0.90, 0.91, 0.92, 0.93, 1.00, 1.01, 2.00, 2.01, 2.02, 2.03, 3.00, 3.01
Timeline
Official Publish:
April 23rd, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.