CVE-2009-0800

NameCVE-2009-0800
DescriptionMultiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1790-1, DSA-1793-1
NVD severitymedium (attack range: remote)
Debian Bugs524806, 524809, 524810

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)jessie (security), jessie0.26.5-2+deb8u4fixed
stretch (security), stretch0.48.0-2+deb9u2fixed
buster, sid0.63.0-2fixed
swftools (PTS)jessie0.9.2+git20130725-2fixed
buster, sid, stretch0.9.2+git20130725-4.1fixed
xpdf (PTS)jessie3.03-17fixed
stretch3.04-4fixed
buster, sid3.04-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kdegraphicssource(unstable)4:4.0medium524810
kdegraphicssourceetch4:3.5.5-3etch3mediumDSA-1793-1
kdegraphicssourcelenny4:3.5.9-3+lenny1mediumDSA-1793-1
popplersource(unstable)0.10.6-1medium524806
popplersourcelenny0.8.7-2medium
swftoolssource(unstable)0.9.2+ds1-2medium
xpdfsource(unstable)3.02-1.4+lenny1medium524809
xpdfsourceetch3.01-9.1+etch6mediumDSA-1790-1
xpdfsourcelenny3.02-1.4+lenny1mediumDSA-1790-1
xpdfsourcesqueeze3.02-1.4+lenny1medium

Search for package or bug name: Reporting problems