CVE-2004-0888
published 2005-01-27CVE-2004-0888: Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a…
PriorityP434critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.33%
94.8th percentile
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.11 | — |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| ascii | ptex | — | — |
| cstex | cstetex | — | — |
| debian | cups | < cups 1.1.22-6 (bookworm) | cups 1.1.22-6 (bookworm) |
| debian | cups | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | cups | — | — |
| debian | debian_linux | — | — |
| debian | xpdf | < cups 1.1.22-6 (bookworm) | cups 1.1.22-6 (bookworm) |
| debian | xpdf | < xpdf 3.00-10 (bookworm) | xpdf 3.00-10 (bookworm) |
| debian | xpdf | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jp38-q8w6-3xm3: The patch for integer overflow vulnerabilities in Xpdf 2
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2005-0206 [CRITICAL] GHSA-jp38-q8w6-3xm3: The patch for integer overflow vulnerabilities in Xpdf 2
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
GHSA
GHSA-3qp4-8w7m-xx2g: Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute a
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2008-1374 [CRITICAL] CWE-190 GHSA-3qp4-8w7m-xx2g: Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute a
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
GHSA
GHSA-x479-x3mc-r9mr: Multiple integer overflows in xpdf 2
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2004-0888 [CRITICAL] GHSA-x479-x3mc-r9mr: Multiple integer overflows in xpdf 2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
GHSA
GHSA-xwjm-m85h-4ff8: Multiple integer overflows in xpdf 3
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2004-0889 [CRITICAL] GHSA-xwjm-m85h-4ff8: Multiple integer overflows in xpdf 3
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
OSV
CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2
osv·2005-04-27·CVSS 10.0
CVE-2005-0206 [CRITICAL] CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
OSV
CVE-2004-0889: Multiple integer overflows in xpdf 3
osv·2005-01-27·CVSS 10.0
CVE-2004-0889 [CRITICAL] CVE-2004-0889: Multiple integer overflows in xpdf 3
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
OSV
CVE-2004-0888: Multiple integer overflows in xpdf 2
osv·2005-01-27·CVSS 10.0
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Red Hat
cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
vendor_redhat·2008-04-01·CVSS 10.0
CVE-2008-1374 [CRITICAL] cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
Debian
CVE-2008-1374: cups - Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, ...
vendor_debian·2008·CVSS 10.0
CVE-2008-1374 [CRITICAL] CVE-2008-1374: cups - Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, ...
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2005-0206: cups - The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-088...
vendor_debian·2005·CVSS 10.0
CVE-2005-0206 [CRITICAL] CVE-2005-0206: cups - The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-088...
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: resolved (fixed in 1.1.22-7)
Ubuntu
xpdf vulnerabilities
vendor_ubuntu·2004-11-02
CVE-2004-0888 xpdf vulnerabilities
Title: xpdf vulnerabilities
Summary: xpdf vulnerabilities
Markus Meissner discovered even more integer overflow vulnerabilities
in xpdf, a viewer for PDF files. These integer overflows can
eventually lead to buffer overflows.
The Common UNIX Printing System (CUPS) uses the same code to print PDF
files; tetex-bin uses the code to generate PDF output and process
included PDF files. In any case, these vulnerabilities could be
exploited by an attacker providing a specially crafted PDF file which,
when processed by CUPS, xpdf, or pdflatex, could result in abnormal
program termination or the execution of program code supplied by the
attacker.
In the case of CUPS, this bug could be exploited to gain the privileges of
the CUPS print server (by default, user cupsys).
In the cases of xpdf and p
Ubuntu
tetex-bin vulnerabilities
vendor_ubuntu·2004-10-28
CVE-2004-0888 tetex-bin vulnerabilities
Title: tetex-bin vulnerabilities
Summary: tetex-bin vulnerabilities
Chris Evans and Marcus Meissner recently discovered several integer
overflow vulnerabilities in xpdf, a viewer for PDF files. Because
tetex-bin contains xpdf code, it is also affected. These
vulnerabilities could be exploited by an attacker providing a
specially crafted TeX, LaTeX, or PDF file. Processing such a file with
pdflatex could result in abnormal program termination or the execution
of program code supplied by the attacker.
This bug could be exploited to gain the privileges of the user
invoking pdflatex.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2004-10-21·CVSS 10.0
CVE-2004-0888 [CRITICAL] security flaw
security flaw
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Red Hat
security flaw
vendor_redhat·2004-10-20·CVSS 10.0
CVE-2005-0206 [CRITICAL] security flaw
security flaw
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
Debian
CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
vendor_debian·2004·CVSS 10.0
CVE-2004-0888 [CRITICAL] CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fixed in 1.1.22-6)
forky: resolved (fixed in 1.1.22-6)
sid: resolved (fixed in 1.1.22-6)
trixie: resolved (fixed in 1.1.22-6)
Debian
CVE-2004-0889: xpdf - Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code su...
vendor_debian·2004·CVSS 10.0
CVE-2004-0889 [CRITICAL] CVE-2004-0889: xpdf - Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code su...
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
Scope: local
bookworm: resolved (fixed in 3.00-10)
bullseye: resolved (fixed in 3.00-10)
forky: resolved (fixed in 3.00-10)
sid: resolved (fixed in 3.00-10)
trixie: resolved (fixed in 3.00-10)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-0888 security flaw
bugzilla·2018-08-16·CVSS 10.0
CVE-2004-0888 [CRITICAL] CVE-2004-0888 security flaw
CVE-2004-0888 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Bugzilla
CVE-2005-0206 security flaw
bugzilla·2018-08-16·CVSS 10.0
CVE-2005-0206 [CRITICAL] CVE-2005-0206 security flaw
CVE-2005-0206 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
Bugzilla
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
bugzilla·2008-03-20·CVSS 10.0
CVE-2008-1374 [CRITICAL] CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
It was discovered that patch applied to cups packages as shipped in Red Hat
Enterprise Linux 3 and 4 to address security issues in xpdf code known as
CVE-2004-0888 / CVE-2005-0206 was incomplete.
On certain platforms, malicious pdf file could still cause a crash or possibly
cause code execution when it's processed by pdftops filter.
This issue affects 64-bit platforms. cups packages in Red Hat Enterprise Linux
5 are not affected by this problem.
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0206.html
Bugzilla
CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)
bugzilla·2005-02-08
[MEDIUM] CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)
CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)
*** This bug has been split off bug 135378 ***
This issue affects RHEL4 as well.
------- Original comment by Mark J. Cox (Security Response Team) on 2004.10.12
07:50 -------
CUPS contains a stripped down version of xpdf. Recent issues have
been found in xpdf 2 that can result in integer overflows causing bad
memory allocation or out of bounds writes. It's not expected these
can cause arbitrary code execution, more likely to be DoS crashers.
Embargoed until October 20th 1400UTC
Patch to follow
CVE names to follow
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to
Bugzilla
CAN-2004-0888 xpdf issues affect cups
bugzilla·2004-10-12
[MEDIUM] CAN-2004-0888 xpdf issues affect cups
CAN-2004-0888 xpdf issues affect cups
CUPS contains a stripped down version of xpdf. Recent issues have
been found in xpdf 2 that can result in integer overflows causing bad
memory allocation or out of bounds writes. It's not expected these
can cause arbitrary code execution, more likely to be DoS crashers.
Embargoed until October 20th 1400UTC
Patch to follow
CVE names to follow
Discussion:
Created attachment 105056
xpdf 2 patch (will require changes to apply against Cups)
---
CAN-2004-0888. Actually my comment about arbitrary code execution is
inaccurate since the flaws could allow you to write an arbitrary byte
at an (almost) arbitrary location. This could possibly lead to
privilege escalation (although it would be hard to do, especially with
Exec-shield).
---
An errata has been
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000886http://marc.info/?l=bugtraq&m=109880927526773&w=2http://marc.info/?l=bugtraq&m=110815379627883&w=2http://www.debian.org/security/2004/dsa-573http://www.debian.org/security/2004/dsa-581http://www.debian.org/security/2004/dsa-599http://www.gentoo.org/security/en/glsa/glsa-200410-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200410-30.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:113http://www.mandriva.com/security/advisories?name=MDKSA-2004:114http://www.mandriva.com/security/advisories?name=MDKSA-2004:115http://www.mandriva.com/security/advisories?name=MDKSA-2004:116http://www.redhat.com/support/errata/RHSA-2004-543.htmlhttp://www.redhat.com/support/errata/RHSA-2004-592.htmlhttp://www.redhat.com/support/errata/RHSA-2005-066.htmlhttp://www.redhat.com/support/errata/RHSA-2005-354.htmlhttp://www.securityfocus.com/bid/11501https://bugzilla.fedora.us/show_bug.cgi?id=2353https://exchange.xforce.ibmcloud.com/vulnerabilities/17818https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9714https://www.ubuntu.com/usn/usn-9-1/http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000886http://marc.info/?l=bugtraq&m=109880927526773&w=2http://marc.info/?l=bugtraq&m=110815379627883&w=2http://www.debian.org/security/2004/dsa-573http://www.debian.org/security/2004/dsa-581http://www.debian.org/security/2004/dsa-599http://www.gentoo.org/security/en/glsa/glsa-200410-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200410-30.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:113http://www.mandriva.com/security/advisories?name=MDKSA-2004:114http://www.mandriva.com/security/advisories?name=MDKSA-2004:115http://www.mandriva.com/security/advisories?name=MDKSA-2004:116http://www.redhat.com/support/errata/RHSA-2004-543.htmlhttp://www.redhat.com/support/errata/RHSA-2004-592.htmlhttp://www.redhat.com/support/errata/RHSA-2005-066.htmlhttp://www.redhat.com/support/errata/RHSA-2005-354.htmlhttp://www.securityfocus.com/bid/11501https://bugzilla.fedora.us/show_bug.cgi?id=2353https://exchange.xforce.ibmcloud.com/vulnerabilities/17818https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9714https://www.ubuntu.com/usn/usn-9-1/
2005-01-27
Published