CVE-2009-0165: Integer Overflow
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "gallocn."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0165?
The severity of CVE-2009-0165 is considered to be relatively high due to its potential for exploitation in specific environments.
How do I fix CVE-2009-0165?
To fix CVE-2009-0165, upgrade to a version of Xpdf or XpdfReader that is newer than 3.02, as these versions contain the necessary patches.
What impact does CVE-2009-0165 have on my system?
CVE-2009-0165 can potentially allow an attacker to execute arbitrary code or cause denial of service on affected systems via specially crafted files.
Which versions of Xpdf are affected by CVE-2009-0165?
Affected versions of Xpdf include 0.5a, 0.7a, 0.91a, 0.91b, 0.91c, 0.92a, 0.92b, 0.92c, 0.92d, 0.92e, 0.93a, 0.93b, 0.93c, and all versions up to 3.02.
Is Poppler affected by CVE-2009-0165?
No, the Poppler library itself is not affected by CVE-2009-0165 as it does not contain the vulnerable JBIG2 decoder.