CVE-2009-0756

poppler < 0.10.4 - Denial of Service via JBIG2 Symbol Dictionary Parsing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0756. PoCs published by Romario.

AI-analyzed exploit summary The provided text describes a denial-of-service vulnerability in Poppler versions prior to 0.10.4, triggered by malformed PDF files. It references a binary exploit (32800.pdf) but does not contain executable code.

Description

The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Romario · textdoslinux
https://www.exploit-db.com/exploits/32800

The provided text describes a denial-of-service vulnerability in Poppler versions prior to 0.10.4, triggered by malformed PDF files. It references a binary exploit (32800.pdf) but does not contain executable code.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Poppler < 0.10.4
No auth needed
Prerequisites: A malformed PDF file · Target application using vulnerable Poppler library
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33749
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33853
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/02/19/2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/02/13/1
Third Party Advisory x_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2009-0059
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35685
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502761/100/0/threaded

Scores

EPSS 0.1485
EPSS Percentile 94.6%

Details

Status published
Products (34)
poppler/poppler 0.1
poppler/poppler 0.1.1
poppler/poppler 0.1.2
poppler/poppler 0.2.0
poppler/poppler 0.3.0
poppler/poppler 0.3.1
poppler/poppler 0.3.2
poppler/poppler 0.3.3
poppler/poppler 0.4.0
poppler/poppler 0.4.1
... and 24 more
Published Mar 03, 2009
Tracked Since Feb 18, 2026