Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
BID:37350
Info
Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
| Bugtraq ID: | 37350 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-4035 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2009 12:00AM |
| Updated: | Feb 18 2014 05:17AM |
| Credit: | Petr Gajdos and Christian Kornacker |
| Vulnerable: |
Xpdf Xpdf 3.0 pl3 Xpdf Xpdf 3.0 pl2 Xpdf Xpdf 3.0 1pl1 Xpdf Xpdf 3.0 1 Xpdf Xpdf 3.0 0 SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 11 SuSE SUSE Linux Enterprise Desktop 10 SP3 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux AS 4 Gentoo Linux |
| Not Vulnerable: |
Xpdf Xpdf 3.01 |
Discussion
Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
Xpdf is prone to a buffer-overflow vulnerability.
Exploits may allow remote attackers to execute arbitrary code in the context of an affected application or cause denial-of-service conditions.
Xpdf is prone to a buffer-overflow vulnerability.
Exploits may allow remote attackers to execute arbitrary code in the context of an affected application or cause denial-of-service conditions.
Exploit / POC
Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Xpdf 'FoFiType1::parse' Buffer Overflow Vulnerability
References:
References:
- Bug 541614 - (CVE-2009-4035) CVE-2009-4035 xpdf: buffer overflow in FoFiType1::p (Red Hat)
- Poppler Homepage (Poppler)
- Xpdf Homepage (Xpdf)
- diff --git a/fofi/FoFiType1.cc b/fofi/FoFiType1.cc (Poppler)