CVE-2009-0800: Input Validation
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
Other sources
Multiple input validation flaws were discovered in xpdf's JBIG2 decoder. These flaws could lead to arbitrary code execute with the permissions of the user running xpdf.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting these flaws.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0800?
CVE-2009-0800 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2009-0800?
To fix CVE-2009-0800, update the affected software to the latest version that has addressed the JBIG2 decoder flaws.
What software is affected by CVE-2009-0800?
CVE-2009-0800 affects Xpdf versions 3.02pl2 and earlier, CUPS versions 1.3.9 and earlier, and certain versions of Poppler among others.
Can CVE-2009-0800 be exploited remotely?
Yes, CVE-2009-0800 can be exploited remotely through specially crafted PDF files.
What are the risks associated with CVE-2009-0800?
The risks of CVE-2009-0800 include the potential for attackers to execute arbitrary code on the affected system.