CVE Database
/

CVE-2009-4035

Back to search

CVE-2009-4035

Published: Dec 21, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

1023356
vdb-entry
x_refsource_SECTRACK
RHSA-2009:1680
vendor-advisory
x_refsource_REDHAT
37350
vdb-entry
x_refsource_BID
37787
third-party-advisory
x_refsource_SECUNIA
37793
third-party-advisory
x_refsource_SECUNIA
xpdf-fofitype1parse-bo(54831)
vdb-entry
x_refsource_XF
37781
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1682
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:10996
vdb-entry
signature
x_refsource_OVAL
SUSE-SR:2010:003
vendor-advisory
x_refsource_SUSE
RHSA-2009:1681
vendor-advisory
x_refsource_REDHAT
37641
third-party-advisory
x_refsource_SECUNIA
ADV-2009-3555
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now