Xpdf.Splash.DrawImage.Integer.Overflow

Release DateDec 17, 2009
SeverityCritical
ImpactSystem Compromise
Denial of Service
DescriptionThis indicates an attack attempt against an integer-overflow vulnerability in Xpdf.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted PDF document. It allows a remote attacker to cause a denial of service (application crash) or possibly execute arbitrary code.
Affected ProductsXpdf Xpdf 3.0 pl3 and previous versions
Recommended ActionsApply the patch available at the following website:
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl4.patch
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3604
Reference/shttp://www.securityfocus.com/bid/36703 (BugTraq)
http://secunia.com/advisories/37053/
http://www.vupen.com/english/advisories/2009/2924
Reference: VID-18004