CVE-2009-4117: Buffer Overflow
Multiple stack-based buffer overflows in pdfshade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain types of shading that are not properly handled by the (1) pdfloadtype4shade, (2) pdfloadtype5shade, (3) pdfloadtype6shade, and (4) pdfloadtype7shade functions. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4117?
CVE-2009-4117 has a high severity rating due to the potential for remote attackers to execute arbitrary code.
How do I fix CVE-2009-4117?
To fix CVE-2009-4117, upgrade to a version of SumatraPDF that is later than 1.0.1.
What versions of SumatraPDF are affected by CVE-2009-4117?
CVE-2009-4117 affects SumatraPDF versions 0.1 to 0.9.4.
What kind of vulnerability is CVE-2009-4117?
CVE-2009-4117 is classified as a multiple stack-based buffer overflow vulnerability.
Can CVE-2009-4117 lead to a denial of service?
Yes, CVE-2009-4117 can cause a denial of service due to improper handling of shading in PDFs.