CVE-2009-0166: Medium severity Foolabs Xpdf vulnerability
A security flaw was found in the JBIG2 decoder (possibility of freeing of uninitialized memory). An attacker could use this flaw to potentially cause a denial of service (application crash).
Acknowledgements:
Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team for responsibly reporting this flaw.
Other sources
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0166?
CVE-2009-0166 has a medium severity rating due to the potential for denial of service caused by the JBIG2 decoder flaw.
How do I fix CVE-2009-0166?
To fix CVE-2009-0166, users should update to the latest patched version of affected software that addresses this vulnerability.
What are the affected versions in CVE-2009-0166?
CVE-2009-0166 affects various versions of Xpdf, Glyph & Cog XpdfReader, and Poppler prior to version 0.10.5.
Can CVE-2009-0166 cause application crashes?
Yes, CVE-2009-0166 can potentially cause application crashes due to the freeing of uninitialized memory in the JBIG2 decoder.
Is CVE-2009-0166 specific to any particular operating systems?
CVE-2009-0166 is not limited to a specific operating system but affects multiple implementations of the decoding libraries across different platforms.