CVE-2009-3603
21.10.2009, 17:30
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.Enginsight
| Vendor | Product | Version |
|---|---|---|
| foolabs | xpdf | 3.02pl1:pl1 |
| foolabs | xpdf | 3.02pl2:pl2 |
| foolabs | xpdf | 3.02pl3:pl3 |
| glyphandcog | xpdfreader | 3.00 |
| glyphandcog | xpdfreader | 3.01 |
| glyphandcog | xpdfreader | 3.02 |
| poppler | poppler | 𝑥 ≤ 0.12.0 |
| poppler | poppler | 0.1 |
| poppler | poppler | 0.1.1 |
| poppler | poppler | 0.1.2 |
| poppler | poppler | 0.2.0 |
| poppler | poppler | 0.3.0 |
| poppler | poppler | 0.3.1 |
| poppler | poppler | 0.3.2 |
| poppler | poppler | 0.3.3 |
| poppler | poppler | 0.4.0 |
| poppler | poppler | 0.4.1 |
| poppler | poppler | 0.4.2 |
| poppler | poppler | 0.4.3 |
| poppler | poppler | 0.4.4 |
| poppler | poppler | 0.5.0 |
| poppler | poppler | 0.5.1 |
| poppler | poppler | 0.5.2 |
| poppler | poppler | 0.5.3 |
| poppler | poppler | 0.5.4 |
| poppler | poppler | 0.5.9 |
| poppler | poppler | 0.6.0 |
| poppler | poppler | 0.6.1 |
| poppler | poppler | 0.6.2 |
| poppler | poppler | 0.6.3 |
| poppler | poppler | 0.6.4 |
| poppler | poppler | 0.7.0 |
| poppler | poppler | 0.7.1 |
| poppler | poppler | 0.7.2 |
| poppler | poppler | 0.7.3 |
| poppler | poppler | 0.8.0 |
| poppler | poppler | 0.8.1 |
| poppler | poppler | 0.8.2 |
| poppler | poppler | 0.8.3 |
| poppler | poppler | 0.8.4 |
| poppler | poppler | 0.8.6 |
| poppler | poppler | 0.8.7 |
| poppler | poppler | 0.9.0 |
| poppler | poppler | 0.9.1 |
| poppler | poppler | 0.9.2 |
| poppler | poppler | 0.9.3 |
| poppler | poppler | 0.10.0 |
| poppler | poppler | 0.10.1 |
| poppler | poppler | 0.10.2 |
| poppler | poppler | 0.10.3 |
| poppler | poppler | 0.10.4 |
| poppler | poppler | 0.10.5 |
| poppler | poppler | 0.10.6 |
| poppler | poppler | 0.10.7 |
| poppler | poppler | 0.11.0 |
| poppler | poppler | 0.11.1 |
| poppler | poppler | 0.11.2 |
| poppler | poppler | 0.11.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gpdf |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ipe |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| kdegraphics |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| koffice |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libextractor |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| pdfkit.framework |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| pdftohtml |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| poppler |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| tetex-bin |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| texlive-bin |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| xpdf |
|
Common Weakness Enumeration
References