Integer Overflow Vulnerability in Poppler's JBIG2 Decoding Feature
CVE-2009-1187

Currently unrated

Key Information:

Vendor

Poppler

Status
Vendor
CVE Published:
23 April 2009

What is CVE-2009-1187?

An integer overflow exists in the JBIG2 decoding feature of Poppler, allowing remote attackers to trigger a denial of service by manipulating specific inputs. This vulnerability can potentially enable arbitrary code execution through crafted files, particularly affecting the CairoOutputDev component in Poppler. It emphasizes the necessity of timely software updates to mitigate the risks associated with this flaw.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.