CVE-2009-1605: Buffer Overflow
Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdffunction.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1605?
CVE-2009-1605 has been classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2009-1605?
To mitigate CVE-2009-1605, update to a non-vulnerable version of SumatraPDF, specifically version 0.9.4 or later.
What software is affected by CVE-2009-1605?
CVE-2009-1605 affects versions of MuPDF utilized in SumatraPDF up to and including 0.9.3.
What type of vulnerability is CVE-2009-1605?
CVE-2009-1605 is classified as a heap-based buffer overflow vulnerability.
Can exploiting CVE-2009-1605 lead to data loss?
Yes, exploiting CVE-2009-1605 can potentially lead to data loss as arbitrary code execution may allow attackers to manipulate files and system processes.