CVE-2009-3607
Description
Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Risk Information
Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.855
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Poppler update (ELSA-2024-2979) poppler-20.11.0-11.el8.i686.rpm | Linux |
| Poppler update (ELSA-2024-2979) poppler-20.11.0-11.el8.x86_64.rpm | Linux |
| Poppler-glib update (ELSA-2024-2979) poppler-glib-20.11.0-11.el8.i686.rpm | Linux |
| Poppler-glib update (ELSA-2024-2979) poppler-glib-20.11.0-11.el8.x86_64.rpm | Linux |
| Poppler-qt5 update (ELSA-2024-2979) poppler-qt5-20.11.0-11.el8.i686.rpm | Linux |
| Poppler-qt5 update (ELSA-2024-2979) poppler-qt5-20.11.0-11.el8.x86_64.rpm | Linux |
| Poppler-utils update (ELSA-2024-2979) poppler-utils-20.11.0-11.el8.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234