CVE-2009-1188
kdegraphics - several vulnerabilities
EPSS 7.2%
描述
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
如何修補 CVE-2009-1188
要修補 CVE-2009-1188,請將受影響套件升級到下列已修補版本。
- Debian/kdegraphics—升級至 4:3.5.9-3+lenny3 或更新版本
- Debian/poppler—升級至 0.10.6-1 或更新版本
- —升級至 3.02-2 或更新版本
- —升級至 3.02-1.4+lenny2 或更新版本
CVE-2009-1188 正在被利用嗎?
中等 — EPSS 為 7.2%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 4:3.5.9-3+lenny3
- from 0, < 0.10.6-1
- from 0, < 3.02-2
- from 0, < 3.02-1.4+lenny2