First published: Fri Nov 13 2009(Updated: )
Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Poppler | =0.10.6 | |
Poppler Poppler | =0.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3938 has a moderate severity rating due to its potential to allow denial of service and possible arbitrary code execution.
To mitigate CVE-2009-3938, update to a newer, patched version of Poppler that addresses the buffer overflow vulnerability.
CVE-2009-3938 affects Poppler versions 0.10.6 and 0.12.0.
CVE-2009-3938 enables user-assisted remote attackers to potentially execute arbitrary code or cause a denial of service.
Yes, CVE-2009-3938 is related to the Abiword pdftoabw utility which utilizes the vulnerable Poppler library.