| Title | Xpdf および Poppler の ObjectStream::ObjectStream 関数における整数オーバーフローの脆弱性 |
|---|---|
| Summary | Xpdf および Poppler の ObjectStream::ObjectStream 関数には、PDF ドキュメントの処理に不備があるため、整数オーバーフローの脆弱性が存在します。 |
| Possible impacts | 第三者に任意のコードを実行される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Oct. 15, 2009, midnight |
| Registration Date | Nov. 25, 2009, 12:23 p.m. |
| Last Update | May 26, 2010, 4:31 p.m. |
| CVSS2.0 : 危険 | |
| Score | 9.3 |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| レッドハット |
| Red Hat Enterprise Linux 4 (as) |
| Red Hat Enterprise Linux 4 (es) |
| Red Hat Enterprise Linux 4 (ws) |
| Red Hat Enterprise Linux 4.8 (as) |
| Red Hat Enterprise Linux 4.8 (es) |
| Red Hat Enterprise Linux 5 (server) |
| Red Hat Enterprise Linux Desktop 4.0 |
| Red Hat Enterprise Linux Desktop 5.0 (client) |
| Red Hat Enterprise Linux EUS 5.4.z (server) |
| RHEL Desktop Workstation 5 (client) |
| RHEL Optional Productivity Applications 5 (server) |
| RHEL Optional Productivity Applications EUS 5.4.z (server) |
| サイバートラスト株式会社 |
| Asianux Server 3 (x86) |
| Asianux Server 3 (x86-64) |
| Asianux Server 4.0 |
| Asianux Server 4.0 (x86-64) |
| Glyph & Cog, LLC |
| Xpdf 3.02pl4 未満 |
| freedesktop.org |
| Poppler 0.12.1 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2009年11月25日] 掲載 [2010年05月26日] ベンダ情報:ミラクル・リナックス (tetex-3.0-33.8.5.0.1.AXS3) を追加 ベンダ情報:レッドハット (RHSA-2010:0400) を追加 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. |
|---|---|
| Summary | Desbordamiento de entero en la función ObjectStream::ObjectStream en XRef.cc en Xpdf y Poppler, usado en GPdf, kdegraphics KPDF, y CUPS pdftopf y teTeX, podría permitir a atacantes remotos ejecutar código de su elección a través de un documento PDF manipulado que provoca un desbordamiento de búfer basado en memoria dinámica (heap). |
| Publication Date | Oct. 22, 2009, 2:30 a.m. |
| Registration Date | Jan. 29, 2021, 1:24 p.m. |
| Last Update | April 23, 2026, 9:35 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:foolabs:xpdf:3.02pl1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:foolabs:xpdf:3.02pl2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:foolabs:xpdf:3.02pl3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:glyphandcog:xpdfreader:3.00:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:glyphandcog:xpdfreader:3.01:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:glyphandcog:xpdfreader:3.02:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:*:*:*:*:*:*:*:* | 0.12.0 | ||||
| cpe:2.3:a:poppler:poppler:0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.3.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.3.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.3.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.4.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.4.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.4.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.5.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.6.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.6.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.6.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.6.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.7.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.7.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.7.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.7.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.8.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.9.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.9.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.9.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.9.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.10.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.11.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.11.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.11.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:poppler:poppler:0.11.3:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |