Description
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and
other products allows remote attackers to cause a denial of service (crash)
via a crafted PDF file that triggers a free of uninitialized memory.
Notes
| kees | this is also CVE-2009-0146, CVE-2009-0147, but not CVE-2009-0165.
http://idisk.mac.com/drew_yao-Public/jbig2.zip |
| mdeslaur | our cups uses the system pdftops, so we're not affected |
| jdstrand | CUPS compiled with --disable-pdftops |
| sbeattie | ipe uses system pdflatex |
Package
Priority: Negligible
Patches:
Package
Priority: Negligible
| Upstream: | released
(1.3.10)
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | not-affected
(linked to poppler)
|
| Ubuntu 18.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 20.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 21.10: | not-affected
(linked to poppler)
|
| Ubuntu 16.04 ESM: | not-affected
(linked to poppler)
|
| Ubuntu 22.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 14.04 ESM: | DNE
(trusty was not-affected [linked to poppler])
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
Priority: Low
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 20.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 21.10: | not-affected
(linked to poppler)
|
| Ubuntu 16.04 ESM: | not-affected
(linked to poppler)
|
| Ubuntu 22.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 14.04 ESM: | DNE
(trusty was not-affected [linked to poppler])
|
Patches:
Updated: 2022-04-25 00:14:20 UTC (commit ecc1009cb19540b950de59270950018900f37f15)