CVE-2009-3608
EPSS 10.2%
描述
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
如何修補 CVE-2009-3608
要修補 CVE-2009-3608,請將受影響套件升級到下列已修補版本。
- Debian/poppler—升級至 0.12.2-1 或更新版本
- Debian/xpdf—升級至 3.02-2 或更新版本
CVE-2009-3608 正在被利用嗎?
中等 — EPSS 為 10.2%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 0.12.2-1
- from 0, < 3.02-2