CVE-2009-1188: Integer Overflow
An integer overflow was found in poppler's SplashBitmap::SplashBitmap method. A malicious PDF file could cause poppler to execute with permissions of the user calling the library.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting this flaw.
Other sources
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-1188?
CVE-2009-1188 is classified with a high severity due to its potential for allowing remote code execution through malicious PDF files.
How do I fix CVE-2009-1188?
To fix CVE-2009-1188, update to a patched version of Poppler that addresses the integer overflow vulnerability.
Which versions of Poppler are affected by CVE-2009-1188?
CVE-2009-1188 affects multiple Poppler versions, including 0.1.0 up to 0.10.5.
What type of vulnerability is CVE-2009-1188?
CVE-2009-1188 is an integer overflow vulnerability that can lead to code execution.
Can CVE-2009-1188 impact system security?
Yes, CVE-2009-1188 can impact system security by enabling attackers to execute arbitrary code with the privileges of the user running the vulnerable application.