CVE-2009-0791
Publication date 9 June 2009
Last updated 24 July 2024
Ubuntu priority
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.
Status
Package | Ubuntu Release | Status |
---|---|---|
cups | 9.04 jaunty |
Not affected
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
cupsys | 9.04 jaunty | Not in release |
8.10 intrepid | Not in release | |
8.04 LTS hardy |
Not affected
|
|
6.06 LTS dapper |
Not affected
|