CVE-2009-3938
NONE EPSS 91.6%
Published Nov 13, 200916y ago · Modified Jun 16, 20262w ago
Published Nov 13, 2009 16y ago
Last Modified Jun 16, 2026 2w ago
Description
Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file.
Threat Intelligence
EPSS Exploit Probability
91.6% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety
Affected Products 2
References 9
- bugs.debian.org http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534680
- bugs.freedesktop.org http://bugs.freedesktop.org/attachment.cgi?id=30599&action=edit
- bugs.freedesktop.org http://bugs.freedesktop.org/show_bug.cgi?id=23074
- secunia.com http://secunia.com/advisories/37333
- debian.org http://www.debian.org/security/2009/dsa-1941
- mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2011:175
- securityfocus.com http://www.securityfocus.com/bid/36976
- vupen.com http://www.vupen.com/english/advisories/2009/3227
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/54215
Remediation
- bugs.freedesktop.org http://bugs.freedesktop.org/attachment.cgi?id=30599&action=edit