Integer Overflow Vulnerability in Poppler PDF Rendering Library
CVE-2009-3607

Currently unrated

Key Information:

Vendor

Poppler

Status
Vendor
CVE Published:
21 October 2009

What is CVE-2009-3607?

The Poppler PDF rendering library contains an integer overflow vulnerability in the create_surface_from_thumbnail_data function. This flaw can be exploited by remote attackers to induce a denial of service through memory corruption or potentially allow arbitrary code execution by crafting a malicious PDF document, which triggers a heap-based buffer overflow during the processing of thumbnail data.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.