Integer Overflow Vulnerability in Xpdf and Poppler Products
CVE-2009-3603

Currently unrated

Key Information:

Vendor

Poppler

Vendor
CVE Published:
21 October 2009

What is CVE-2009-3603?

An integer overflow exists in the SplashBitmap::SplashBitmap function within Xpdf versions prior to 3.02pl4 and Poppler versions earlier than 0.12.1. This vulnerability can be exploited by remote attackers through the use of specially crafted PDF documents, leading to a potential heap-based buffer overflow. The root of the issue is attributed to an incomplete fix related to previous vulnerabilities, allowing unintended code execution.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.