FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

xpdf -- multiple vulnerabilities

Affected packages
xpdf < 3.02_11

Details

VuXML ID a21037d5-2c38-11de-ab3b-0017a4cccfc6
Discovery 2009-04-16
Entry 2009-04-18
Modified 2009-04-18

Secunia reports:

Some vulnerabilities have been reported in Xpdf, which can be exploited by malicious people to potentially compromise a user's system.

A boundary error exists when decoding JBIG2 symbol dictionary segments. This can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code.

Multiple integer overflows in the JBIG2 decoder can be exploited to potentially execute arbitrary code.

Multiple boundary errors in the JBIG2 decoder can be exploited to cause buffer overflows and potentially execute arbitrary code.

Multiple errors in the JBIG2 decoder can be exploited can be exploited to free arbitrary memory and potentially execute arbitrary code.

Multiple unspecified input validation errors in the JBIG2 decoder can be exploited to potentially execute arbitrary code.

References

CVE Name CVE-2009-0146
CVE Name CVE-2009-0147
CVE Name CVE-2009-0166
CVE Name CVE-2009-0799
CVE Name CVE-2009-0800
CVE Name CVE-2009-1179
CVE Name CVE-2009-1180
CVE Name CVE-2009-1181
CVE Name CVE-2009-1182
CVE Name CVE-2009-1183
URL http://secunia.com/advisories/34291
URL http://www.vupen.com/english/advisories/2009/1065