CVE-2009-0756: Medium severity Poppler Poppler vulnerability
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0756?
CVE-2009-0756 is classified as a denial of service vulnerability that can cause application crashes.
How do I fix CVE-2009-0756?
To fix CVE-2009-0756, upgrade Poppler to version 0.10.4 or later.
Which versions of Poppler are affected by CVE-2009-0756?
CVE-2009-0756 affects Poppler versions prior to 0.10.4, including versions like 0.7.3, 0.7.1, and 0.10.1.
What kind of attack can exploit CVE-2009-0756?
CVE-2009-0756 can be exploited by attackers using specially crafted PDF files that trigger parsing errors.
Is there a workaround for CVE-2009-0756?
The most effective workaround for CVE-2009-0756 is to avoid opening untrusted PDF files until the software is updated.