VulnerabilityModified
CVE-2009-1180
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
MEDIUM 6.8EPSS 5.41%
Does this matter?
Lower severity and a low EPSS score (5.41%). Track it; it rarely justifies an emergency change on its own.
Description
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 5.41% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- foolabs/xpdf · glyphandcog/xpdfreader · poppler/poppler · apple/cups
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
- http://poppler.freedesktop.org/releases.htmlPatch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2009-0458.htmlPatch
- http://secunia.com/advisories/34291Vendor Advisory
- http://secunia.com/advisories/34481Vendor Advisory
- http://secunia.com/advisories/34746Vendor Advisory
- http://secunia.com/advisories/34755Vendor Advisory
- http://secunia.com/advisories/34756Vendor Advisory
- http://secunia.com/advisories/34852Vendor Advisory
- http://secunia.com/advisories/34959Vendor Advisory
- http://secunia.com/advisories/34963Vendor Advisory
- http://secunia.com/advisories/34991Vendor Advisory
- http://secunia.com/advisories/35037Vendor Advisory
- http://secunia.com/advisories/35064Vendor Advisory
- http://secunia.com/advisories/35065Vendor Advisory
- http://secunia.com/advisories/35618Vendor Advisory
- http://secunia.com/advisories/35685Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477
- http://www.debian.org/security/2009/dsa-1790Patch
- http://www.debian.org/security/2009/dsa-1793Patch
- http://www.kb.cert.org/vuls/id/196617US Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:101
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:087
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:175
- http://www.redhat.com/support/errata/RHSA-2009-0429.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2009-0430.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2009-0431.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2009-0480.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.