Vulnerability Name: | CVE-2009-3938 (CCN-54215) | ||||||||||||||||||||
Assigned: | 2009-06-26 | ||||||||||||||||||||
Published: | 2009-06-26 | ||||||||||||||||||||
Updated: | 2017-08-17 | ||||||||||||||||||||
Summary: | Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file. | ||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:UR)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:UR)
| ||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: CCN Type: Debian Bug report logs - #534680 libpoppler4: buffer overflow in the Abiword backend Source: CONFIRM Type: Exploit http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534680 Source: MISC Type: Patch http://bugs.freedesktop.org/attachment.cgi?id=30599&action=edit Source: CONFIRM Type: Exploit http://bugs.freedesktop.org/show_bug.cgi?id=23074 Source: MITRE Type: CNA CVE-2009-3938 Source: CCN Type: Poppler Web site Poppler Source: CCN Type: SA37333 Poppler "pdftoabw" Buffer Overflow Vulnerabilities Source: SECUNIA Type: Vendor Advisory 37333 Source: DEBIAN Type: UNKNOWN DSA-1941 Source: DEBIAN Type: DSA-1941 poppler -- several vulnerabilities Source: MANDRIVA Type: UNKNOWN MDVSA-2011:175 Source: CCN Type: OSVDB ID: 59936 Poppler pdftoabw Utility poppler/ABWOutputDev.cc ABWOutputDev::endWord Function PDF File Handling Overflow Source: BID Type: UNKNOWN 36976 Source: CCN Type: BID-36976 Poppler 'ABWOutputDev.cc' Remote Buffer Overflow Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2009-3227 Source: XF Type: UNKNOWN poppler-abwoutputdev-bo(54215) Source: XF Type: UNKNOWN poppler-abwoutputdev-bo(54215) Source: SUSE Type: SUSE-SR:2009:020 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |