← Back

CVE-2009-0146

nvd nist
Published: Apr 23, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.

Affected (106)

1 product
Xpdf
1 product
Xpdfreader
1 product
Cups
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Foolabs
Version 0.5a
Version 0.7a
Version 0.91a
Version 0.91b
Version 0.91c
Version 0.92a
Version 0.92b
Version 0.92c
Version 0.92d
Version 0.92e
Version 0.93a
Version 0.93b
Version 0.93c
Version 1.00a
Glyphandcog
Up to 3.02
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.80
Version 0.90
Version 0.91
Version 0.92
Version 0.93
Version 1.00
Version 1.01
Version 2.00
Version 2.01
Version 2.02
Version 2.03
Version 3.00
Version 3.01
Configuration B
72 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 1.3.9
Version 1.1.10-1
Version 1.1.10
Version 1.1.11
Version 1.1.12
Version 1.1.13
Version 1.1.14
Version 1.1.15
Version 1.1.16
Version 1.1.17
Version 1.1.18
Version 1.1.19
Version 1.1.19 rc1
Version 1.1.19 rc2
Version 1.1.19 rc3
Version 1.1.19 rc4
Version 1.1.19 rc5
Version 1.1.1
Version 1.1.20
Version 1.1.20 rc1
Version 1.1.20 rc2
Version 1.1.20 rc3
Version 1.1.20 rc4
Version 1.1.20 rc5
Version 1.1.20 rc6
Version 1.1.21
Version 1.1.21 rc1
Version 1.1.21 rc2
Version 1.1.22
Version 1.1.22 rc1
Version 1.1.22 rc2
Version 1.1.23
Version 1.1.23 rc1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5-1
Version 1.1.5-2
Version 1.1.5
Version 1.1.6-1
Version 1.1.6-2
Version 1.1.6-3
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.1.9-1
Version 1.1.9
Version 1.1
Version 1.2.0
Version 1.2.10
Version 1.2.11
Version 1.2.12
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9
Version 1.3.0
Version 1.3.10
Version 1.3.11
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4
Version 1.3.5
Version 1.3.6
Version 1.3.7
Version 1.3.8

References (102)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.