[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-4035Date: (C)2009-12-21   (M)2023-12-22


The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023356
BID-37350
SECUNIA-37641
SECUNIA-37781
SECUNIA-37787
SECUNIA-37793
ADV-2009-3555
RHSA-2009:1680
RHSA-2009:1681
RHSA-2009:1682
SUSE-SR:2010:003
http://cgit.freedesktop.org/poppler/poppler/diff/fofi/FoFiType1.cc?id=4b4fc5c0
http://cgit.freedesktop.org/poppler/poppler/tree/fofi/FoFiType1.cc?id=4b4fc5c017bf147c9069bbce32fc14467bd2a81a
https://bugzilla.redhat.com/show_bug.cgi?id=541614
oval:org.mitre.oval:def:10996
xpdf-fofitype1parse-bo(54831)

CWE    1
CWE-94
OVAL    9
oval:org.secpod.oval:def:200392
oval:org.secpod.oval:def:200470
oval:org.secpod.oval:def:200345
oval:org.secpod.oval:def:500578
...

© SecPod Technologies