CVE-2009-0195: Buffer Overflow
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-0195?
CVE-2009-0195 is classified as a critical vulnerability due to the possibility of remote code execution as a result of a heap-based buffer overflow.
How do I fix CVE-2009-0195?
To remediate CVE-2009-0195, update your Xpdf and CUPS installations to the recommended versions that address the vulnerability.
Which software is affected by CVE-2009-0195?
CVE-2009-0195 affects Xpdf versions 3.02pl2 and earlier, as well as CUPS version 1.3.9.
Can CVE-2009-0195 be exploited by a remote attacker?
Yes, CVE-2009-0195 can be exploited by remote attackers through the delivery of specially crafted PDF files.
What types of systems are at risk for CVE-2009-0195?
Systems running vulnerable versions of Xpdf and CUPS are at risk for exploitation due to CVE-2009-0195.