Back to Database
Status published
Medium
CVE-2009-1179
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and...
Vulnerability Description
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-1179
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2009/dsa-1793
- http://secunia.com/advisories/34963
- http://support.apple.com/kb/HT3639
- http://www.debian.org/security/2009/dsa-1790
- http://secunia.com/advisories/35037
- http://www.vupen.com/english/advisories/2009/1077
- http://www.vupen.com/english/advisories/2009/1621
- http://secunia.com/advisories/35064
- http://www.vupen.com/english/advisories/2009/1066
- http://secunia.com/advisories/34481
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
- http://www.redhat.com/support/errata/RHSA-2009-0431.html
- http://www.vupen.com/english/advisories/2009/1065
- http://www.redhat.com/support/errata/RHSA-2009-0430.html
- http://www.vupen.com/english/advisories/2009/1522
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html
- http://secunia.com/advisories/35618
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
- http://secunia.com/advisories/35065
- https://bugzilla.redhat.com/show_bug.cgi?id=495889
- http://www.redhat.com/support/errata/RHSA-2009-0480.html
- http://poppler.freedesktop.org/releases.html
- http://www.securityfocus.com/bid/34568
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:175
- http://www.kb.cert.org/vuls/id/196617
- http://www.vupen.com/english/advisories/2010/1040
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
- http://rhn.redhat.com/errata/RHSA-2009-0458.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html
- http://secunia.com/advisories/34991
- http://secunia.com/advisories/35379
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:101
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:087
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://secunia.com/advisories/35685
- http://www.vupen.com/english/advisories/2009/1076
- http://secunia.com/advisories/34756
- http://secunia.com/advisories/34291
- http://secunia.com/advisories/34755
- http://secunia.com/advisories/34852
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html
- http://secunia.com/advisories/34959
- http://support.apple.com/kb/HT3613
- http://secunia.com/advisories/34746
- http://www.redhat.com/support/errata/RHSA-2009-0429.html
- http://www.securitytracker.com/id?1022073
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11892
More from foolabs
View All →CVE-2009-3609
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf...
Medium
4.3
CVE-2009-3608
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf...
Critical
9.3
CVE-2009-3606
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4,...
Critical
9.3
CVE-2009-3604
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x...
Critical
9.3
CVE-2009-3603
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before...
Critical
9.3
Affected Vendor
foolabs
View all reports →Affected Software
xpdf, xpdfreader, poppler, cups
Vulnerable Versions:
0.5a, 0.7a, 0.91a, 0.91b, 0.91c, 0.92a, 0.92b, 0.92c, 0.92d, 0.92e, 0.93a, 0.93b, 0.93c, 1.00a, 0, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.80, 0.90, 0.91, 0.92, 0.93, 1.00, 1.01, 2.00, 2.01, 2.02, 2.03, 3.00, 3.01, 0.1, 0.1.1, 0.1.2, 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.3.3, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.9, 0.5.90, 0.5.91, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.6, 0.8.7, 0.9.0, 0.9.1, 0.9.2, 0.9.3, 0.10.0, 0.10.1, 0.10.2, 0.10.3, 0.10.4, 1.1, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.5-1, 1.1.5-2, 1.1.6, 1.1.6-1, 1.1.6-2, 1.1.6-3, 1.1.7, 1.1.8, 1.1.9, 1.1.9-1, 1.1.10, 1.1.10-1, 1.1.11, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19, 1.1.20, 1.1.21, 1.1.22, 1.1.23, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.12, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.10, 1.3.11
Timeline
Official Publish:
April 23rd, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.