CVE-2009-0799 is an out-of-bounds read vulnerability in the JBIG2 decoder affecting Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products. An unauthenticated remote attacker can exploit this by providing a crafted PDF file, leading to a denial of service (crash). The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and low impact, specifically affecting availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.5a:*:*:*:*:*:*:* | ||
0.7aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.7a:*:*:*:*:*:*:* | ||
0.91aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91a:*:*:*:*:*:*:* | ||
0.91bCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91b:*:*:*:*:*:*:* | ||
0.91cCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.