CVE-2009-0146: Buffer Overflow
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.
Other sources
Multiple buffer overflows were found in the JBIG2 decoder. An attacker could use these flaws to cause a denial of service (application crash) via specially-crafted PDF file.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0146?
CVE-2009-0146 is considered to be of high severity due to its potential to cause denial of service via buffer overflows.
How do I fix CVE-2009-0146?
To fix CVE-2009-0146, update to the latest version of affected software, such as Xpdf or CUPS.
What products are affected by CVE-2009-0146?
CVE-2009-0146 affects multiple versions of the Xpdf and CUPS software, specifically versions prior to 1.3.10.
What kind of attack does CVE-2009-0146 enable?
CVE-2009-0146 enables attackers to execute a denial of service by crashing the application with maliciously crafted PDF files.
Where can I find more information about CVE-2009-0146?
More detailed information about CVE-2009-0146 can typically be found in security advisories and vulnerability databases.