Bug 26047 - CVE-2009-0791 - multiple integer overflows
Summary: CVE-2009-0791 - multiple integer overflows
Status: RESOLVED FIXED
Alias: None
Product: poppler
Classification: Unclassified
Component: general (show other bugs)
Version: unspecified
Hardware: Other All
: medium normal
Assignee: poppler-bugs
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-01-14 11:36 UTC by Gabriel Burt
Modified: 2010-01-14 15:22 UTC (History)
0 users

See Also:
i915 platform:
i915 features:


Attachments
Patch against poppler 0.10.1 (138.79 KB, patch)
2010-01-14 11:38 UTC, Gabriel Burt
Details | Splinter Review

Description Gabriel Burt 2010-01-14 11:36:14 UTC
From http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0791

"Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179."
Comment 1 Gabriel Burt 2010-01-14 11:38:20 UTC
Created attachment 32641 [details] [review]
Patch against poppler 0.10.1

This patch was written by Bin Li <bili@novell.com>
Comment 2 Albert Astals Cid 2010-01-14 14:15:46 UTC
0.10.1 is old, we are at 0.12.3 already and that CVE was already fixed, what's the point of this report?
Comment 3 Gabriel Burt 2010-01-14 14:58:56 UTC
Ok, I didn't see any mention of CVE-2009-0791 in the git log or the release notes.  Can you point me to where I could have found out this CVE was already fixed?

The point of the patch is to share a downstream patch that, if the bug wasn't already apparently fixed, might be useful for fixing it in master.
Comment 4 Albert Astals Cid 2010-01-14 15:22:29 UTC
There is no mention, i don't care much about CVE, i just fix the code and that's all. In my opinion CVEs are just a way to make money about bugs in programs.

Of course you could have had a look at the code, but you preferred me to loose my time instead of you losing it.

And hoping a patch of a release that is 15 months old will still apply is in my opinion hoping too much :D

Sharing is good, but not 15 months after.


Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.