|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
 |
Vulnerability Note VU#196617
Xpdf and poppler contain multiple vulnerabilities in the processing of JBIG2 data
OverviewXpdf and poppler contain multiple vulnerabilities, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
I. DescriptionXpdf is an open source viewer for Portable Document Format (PDF) files. Several PDF viewing applications and libraries, such as poppler, are based on the Xpdf code. Xpdf contains multiple vulnerabilities related to the handling of PDF files that contain JBIG2 data. The vulnerabilities include, but are not limited to, a buffer overflow, an integer overflow, a null pointer dereference, and an infinite loop.II. ImpactBy convincing a user to open a malicious PDF file, an attacker may be able to execute code or cause a vulnerable PDF viewer to crash. The PDF could be emailed as an attachment or hosted on a website.III. SolutionApply an update
These issues are addressed in Xpdf 3.02-pl3 and poppler 0.10.6. Please check with your vendor for software updates.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| Apple Computer, Inc. | Vulnerable | 2009-02-23 | 2009-05-13 |
| Artifex Software, Inc. | Unknown | 2009-02-23 | 2009-02-23 |
| Conectiva Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Cray Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Debian GNU/Linux | Vulnerable | 2009-04-06 | 2009-05-06 |
| EMC Corporation | Unknown | 2009-04-06 | 2009-04-06 |
| Engarde Secure Linux | Unknown | 2009-04-06 | 2009-04-06 |
| F5 Networks, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Fedora Project | Vulnerable | 2009-04-06 | 2009-04-16 |
| Foxit Software Company | Unknown | 2009-02-23 | 2009-02-23 |
| Fujitsu | Unknown | 2009-04-06 | 2009-04-06 |
| Gentoo Linux | Vulnerable | | 2009-04-16 |
| Google | Unknown | 2009-02-23 | 2009-04-08 |
| Hewlett-Packard Company | Unknown | 2009-04-06 | 2009-04-06 |
| Hitachi | Unknown | 2009-04-06 | 2009-04-06 |
| IBM Corporation | Unknown | 2009-04-06 | 2009-04-06 |
| IBM Corporation (zseries) | Unknown | 2009-04-06 | 2009-04-06 |
| IBM eServer | Unknown | 2009-04-06 | 2009-04-06 |
| Ingrian Networks, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Juniper Networks, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Mandriva S. A. | Vulnerable | 2009-04-06 | 2009-04-29 |
| Microsoft Corporation | Unknown | 2009-04-06 | 2009-04-06 |
| MontaVista Software, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| NEC Corporation | Unknown | 2009-04-06 | 2009-04-06 |
| NetBSD | Unknown | 2009-04-06 | 2009-04-06 |
| Nokia | Unknown | 2009-04-06 | 2009-04-06 |
| Novell, Inc. | Vulnerable | 2009-03-12 | 2009-04-16 |
| Poppler | Vulnerable | | 2009-04-16 |
| QNX, Software Systems, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Red Hat, Inc. | Vulnerable | 2009-03-12 | 2009-04-17 |
| Research in Motion (RIM) | Vulnerable | 2009-03-31 | 2009-04-16 |
| Silicon Graphics, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| Slackware Linux Inc. | Vulnerable | 2009-04-06 | 2009-04-16 |
| Sony Corporation | Unknown | 2009-04-06 | 2009-04-06 |
| Sun Microsystems, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| SUSE Linux | Vulnerable | 2009-03-30 | 2009-04-16 |
| The SCO Group | Unknown | 2009-04-06 | 2009-04-06 |
| Turbolinux | Vulnerable | 2009-04-06 | 2009-04-16 |
| Ubuntu | Vulnerable | 2009-03-12 | 2009-04-16 |
| Unisys | Unknown | 2009-04-06 | 2009-04-06 |
| Wind River Systems, Inc. | Unknown | 2009-04-06 | 2009-04-06 |
| xpdf | Vulnerable | 2009-02-23 | 2009-04-16 |
| Yahoo, Inc. | Unknown | 2009-02-23 | 2009-02-23 |
References
http://www.us-cert.gov/cas/tips/ST04-010.html
http://www.cert.org/tech_tips/securing_browser/
http://cgit.freedesktop.org/poppler/poppler/commit/?id=9f1312f3d7dfa7e536606a7c7296b7c876b11c00
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl3.patch
http://www.ubuntu.com/usn/usn-759-1
http://blackberry.com/btsc/KB17953
http://rhn.redhat.com/errata/RHSA-2009-0429.html
http://rhn.redhat.com/errata/RHSA-2009-0431.html
http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:101
http://www.debian.org/security/2009/dsa-1790
http://support.apple.com/kb/HT3549
http://secunia.com/advisories/34291/
http://www.securitytracker.com/alerts/2009/Apr/1022072.html
http://www.securityfocus.com/bid/34568
http://jvn.jp/cert/JVNVU196617/index.html
Credit
These vulnerabilities were reported by Will Dormann of the CERT/CC.
This document was written by Will Dormann.
Other Information
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|