VulnerabilityModified
CVE-2009-1182
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
HIGH 7.5EPSS 7.35%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.35% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- foolabs/xpdf · glyphandcog/xpdfreader · poppler/poppler · apple/cups
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
- http://poppler.freedesktop.org/releases.html
- http://rhn.redhat.com/errata/RHSA-2009-0458.htmlVendor Advisory
- http://secunia.com/advisories/34291Vendor Advisory
- http://secunia.com/advisories/34481Vendor Advisory
- http://secunia.com/advisories/34746Vendor Advisory
- http://secunia.com/advisories/34755Vendor Advisory
- http://secunia.com/advisories/34756Vendor Advisory
- http://secunia.com/advisories/34852Vendor Advisory
- http://secunia.com/advisories/34959Vendor Advisory
- http://secunia.com/advisories/34963Vendor Advisory
- http://secunia.com/advisories/34991Vendor Advisory
- http://secunia.com/advisories/35037Vendor Advisory
- http://secunia.com/advisories/35064Vendor Advisory
- http://secunia.com/advisories/35065Vendor Advisory
- http://secunia.com/advisories/35618Vendor Advisory
- http://secunia.com/advisories/35685Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477
- http://www.debian.org/security/2009/dsa-1790
- http://www.debian.org/security/2009/dsa-1793
- http://www.kb.cert.org/vuls/id/196617US Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:101
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:087
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:175
- http://www.redhat.com/support/errata/RHSA-2009-0429.html
- http://www.redhat.com/support/errata/RHSA-2009-0430.html
- http://www.redhat.com/support/errata/RHSA-2009-0431.html
- http://www.redhat.com/support/errata/RHSA-2009-0480.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.