suse · CVE-2009-3608

Quick triage

Priority: critical Published: 2021-05-30 12:48:45 UTC Updated: 2026-04-18 20:17:22 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2009-3608 severity critical: SUSE including 93 source package names (libpoppler-cpp0-0.43.0-15.1, libpoppler-cpp0-0.43.0-16.15.1, …), 163 product×package rows across 33 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (33 product lines)): Fixed 163.

Description:

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

cvelogic Threat Intelligence