CVE-2009-0147
Publication date 23 April 2009
Last updated 24 July 2024
Ubuntu priority
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.
Status
Package | Ubuntu Release | Status |
---|---|---|
cups | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty | Not in release | |
cupsys | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
evince | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty | Not in release | |
gpdf | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
ipe | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty | Not in release | |
kdegraphics | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
koffice | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
libextractor | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty |
Not affected
|
|
pdfkit.framework | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
pdftohtml | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
poppler | 16.04 LTS xenial |
Fixed 0.10.5-1ubuntu2
|
14.04 LTS trusty |
Fixed 0.10.5-1ubuntu2
|
|
tetex-bin | 16.04 LTS xenial | Not in release |
14.04 LTS trusty | Not in release | |
texlive-bin | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty | Not in release | |
xpdf | 16.04 LTS xenial |
Not affected
|
14.04 LTS trusty | Not in release | |