CVE-2009-3938: Buffer Overflow
Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3938?
CVE-2009-3938 has a moderate severity rating due to its potential to allow denial of service and possible arbitrary code execution.
How do I fix CVE-2009-3938?
To mitigate CVE-2009-3938, update to a newer, patched version of Poppler that addresses the buffer overflow vulnerability.
Which versions of Poppler are affected by CVE-2009-3938?
CVE-2009-3938 affects Poppler versions 0.10.6 and 0.12.0.
What type of attack does CVE-2009-3938 enable?
CVE-2009-3938 enables user-assisted remote attackers to potentially execute arbitrary code or cause a denial of service.
Is CVE-2009-3938 related to any specific utility?
Yes, CVE-2009-3938 is related to the Abiword pdftoabw utility which utilizes the vulnerable Poppler library.