CVE-2009-0147: Integer Overflow
Multiple integer overflows and one integer signedness error were found in the JBIG2 decoder. An attacker could use these flaws to cause a denial of service (application crash) via specially-crafted PDF file.
Acknowledgements:
Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team for responsibly reporting these flaws.
Other sources
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0147?
CVE-2009-0147 has a severity rating that could lead to denial of service due to application crashes.
How do I fix CVE-2009-0147?
To fix CVE-2009-0147, update your Xpdf or Glyph & Cog XpdfReader to the latest version that addresses this vulnerability.
What versions of Xpdf are affected by CVE-2009-0147?
Xpdf versions 0.5a, 0.7a, 0.91a, 0.91b, 0.91c, 0.92a, 0.92b, 0.92c, 0.92d, 0.92e, 0.93a, 0.93b, 0.93c, and 1.00a are affected by CVE-2009-0147.
Can CVE-2009-0147 be exploited remotely?
Yes, CVE-2009-0147 can be exploited remotely via specially-crafted PDF files.
What is the impact of CVE-2009-0147 on users?
The impact of CVE-2009-0147 on users includes potential crashes of applications using the vulnerable Xpdf components when processing malicious PDF files.