Secunia
|
|

CVE Reference: CVE-2009-4035 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2009-4035 |
|
|
Description: The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/54831 SUSE http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html ST 1023356 SAID Secunia Advisory: SA37641 Secunia Advisory: SA37781 Secunia Advisory: SA37787 Secunia Advisory: SA37793 REDHAT http://www.redhat.com/support/errata/RHSA-2009-1682.html http://www.redhat.com/support/errata/RHSA-2009-1680.html http://www.redhat.com/support/errata/RHSA-2009-1681.html OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10996 MISC http://cgit.freedesktop.org/poppler/poppler/tree/fofi/FoFiType1.cc?id=4b4fc5c017bf147c9069bbce32fc14467bd2a81a CONFIRM http://cgit.freedesktop.org/poppler/poppler/diff/fofi/FoFiType1.cc?id=4b4fc5c0 BID 37350 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |