Integer Overflow Vulnerability in PDF Decoding for Xpdf and Poppler
CVE-2009-1188

Currently unrated

Key Information:

Vendor

Poppler

Status
Vendor
CVE Published:
23 April 2009

What is CVE-2009-1188?

An integer overflow fault exists in the JBIG2 decoding feature within the SplashBitmap::SplashBitmap function found in the SplashBitmap.cc file, affecting Xpdf versions before 3.02pl4 and Poppler versions prior to 0.10.6. This security flaw can be exploited by remote attackers through specially crafted PDF files, leading to the execution of arbitrary code or causing an application crash, which results in a denial of service.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.