Integer Overflow Vulnerability in Multiple Products from Various Vendors
CVE-2009-0791

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
9 June 2009

Summary

The vulnerability involves multiple integer overflow errors in Xpdf versions 2.x and 3.x, as well as Poppler version 0.x. These issues are exploited in the pdftops filter of CUPS versions 1.1.17, 1.1.22, and 1.3.7, allowing remote attackers to create malicious PDF files that trigger heap-based buffer overflows. Attackers leveraging this vulnerability could potentially crash applications or execute arbitrary code, with various components like Decrypt.cxx, FoFiTrueType.cxx, gmem.c, JBIG2Stream.cxx, and PSOutputDev.cxx noted as related vectors.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.