CVE-2009-0756
EPSS 14.9%
Description
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.
How to fix CVE-2009-0756
To remediate CVE-2009-0756, upgrade the affected package to a fixed version below.
- Debian/poppler—upgrade to 0.10.6-1 or later
Is CVE-2009-0756 being exploited?
Moderate — EPSS is 14.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.10.6-1