Back to Database
Status published
Medium
CVE-2009-0195
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9,...
Vulnerability Description
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0195
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/secunia_research/2009-18/
- http://secunia.com/advisories/34963
- http://secunia.com/advisories/35064
- http://secunia.com/advisories/34481
- http://www.securityfocus.com/archive/1/502759/100/0/threaded
- http://www.redhat.com/support/errata/RHSA-2009-0480.html
- http://www.vupen.com/english/advisories/2010/1040
- http://rhn.redhat.com/errata/RHSA-2009-0458.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10076
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:087
- http://secunia.com/advisories/34756
- http://secunia.com/advisories/34291
- http://www.securityfocus.com/archive/1/502762/100/0/threaded
- http://secunia.com/secunia_research/2009-17/
- http://www.securityfocus.com/bid/34791
More from apple
View All →CVE-2022-37724
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary...
Medium
6.1
CVE-2020-24721
An issue was discovered in the GAEN (aka Google/Apple Exposure...
Medium
5.7
CVE-2020-20095
iMessage (Messages app) iOS 12.4 and prior user interface does...
Medium
6.5
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
High
7.5
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
High
7.5
Affected Vendor
apple
View all reports →Affected Software
cups, xpdf, xpdfreader
Vulnerable Versions:
1.3.9, 0.5a, 0.7a, 0.91a, 0.91b, 0.91c, 0.92a, 0.92b, 0.92c, 0.92d, 0.92e, 0.93a, 0.93b, 0.93c, 1.00a, 3.0.1, 0, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.80, 0.90, 0.91, 0.92, 0.93, 1.00, 1.01, 2.00, 2.01, 2.02, 2.03, 3.00
Timeline
Official Publish:
April 23rd, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.