TROYANOSYVIRUS
Retour aux CVEs

CVE-2009-3604

N/A

Description

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.

Details CVE

Score CVSS v3.1N/A
Publie10/21/2009
Derniere modification4/23/2026
Sourcenvd
Observations honeypot0

Produits affectes

foolabs:xpdfglyphandcog:xpdfreadergnome:gpdfkde:kpdfpoppler:poppler

Faiblesses (CWE)

CWE-399

References

ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patch(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37023(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37028(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37037(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37042(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37043(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37053(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37077(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37079(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37114(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37159(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/39327(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/39938(af854a3a-2127-422b-91ae-364da2661108)
http://securitytracker.com/id?1023029(af854a3a-2127-422b-91ae-364da2661108)
http://site.pi3.com.pl/adv/xpdf.txt(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2010/dsa-2028(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2010/dsa-2050(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/36703(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-850-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-850-3(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/2924(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/2928(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/0802(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1040(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2010/1220(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=526911(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1500.html(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1501.html(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1502.html(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1503.html(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1512.html(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.