CVE-2004-0889
published 2005-01-27CVE-2004-0889: Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and…
PriorityP431critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.21%
92.7th percentile
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| apple | cups | >= 0 < 1.1.22-6 | 1.1.22-6 |
| debian | cups | < cups 1.1.22-6 (bookworm) | cups 1.1.22-6 (bookworm) |
| debian | debian_linux | — | — |
| debian | xpdf | < cups 1.1.22-6 (bookworm) | cups 1.1.22-6 (bookworm) |
| debian | xpdf | < xpdf 3.00-10 (bookworm) | xpdf 3.00-10 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xpdf vulnerabilities
vendor_ubuntu·2004-11-02
CVE-2004-0888 xpdf vulnerabilities
Title: xpdf vulnerabilities
Summary: xpdf vulnerabilities
Markus Meissner discovered even more integer overflow vulnerabilities
in xpdf, a viewer for PDF files. These integer overflows can
eventually lead to buffer overflows.
The Common UNIX Printing System (CUPS) uses the same code to print PDF
files; tetex-bin uses the code to generate PDF output and process
included PDF files. In any case, these vulnerabilities could be
exploited by an attacker providing a specially crafted PDF file which,
when processed by CUPS, xpdf, or pdflatex, could result in abnormal
program termination or the execution of program code supplied by the
attacker.
In the case of CUPS, this bug could be exploited to gain the privileges of
the CUPS print server (by default, user cupsys).
In the cases of xpdf and p
Ubuntu
xpdf vulnerabilities
vendor_ubuntu·2004-10-23
CVE-2004-0889 xpdf vulnerabilities
Title: xpdf vulnerabilities
Summary: xpdf vulnerabilities
Chris Evans discovered several integer overflow vulnerabilities in xpdf, a
viewer for PDF files. The Common UNIX Printing System (CUPS) also uses the
same code to print PDF files. In either case, these vulnerabilities could
be exploited by an attacker by providing a specially crafted PDF file which,
when processed by CUPS or xpdf, could result in abnormal program termination
or the execution of program code supplied by the attacker.
In the case of CUPS, this bug could be exploited to gain the privileges of
the CUPS print server (by default, user cupsys).
In the case of xpdf, this bug could be exploited to gain the privileges of
the user invoking xpdf.
Instructions: In general, a standard system update will make all the necessar
Red Hat
security flaw
vendor_redhat·2004-10-21·CVSS 10.0
CVE-2004-0888 [CRITICAL] security flaw
security flaw
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Debian
CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
vendor_debian·2004·CVSS 10.0
CVE-2004-0888 [CRITICAL] CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fixed in 1.1.22-6)
forky: resolved (fixed in 1.1.22-6)
sid: resolved (fixed in 1.1.22-6)
trixie: resolved (fixed in 1.1.22-6)
Debian
CVE-2004-0889: xpdf - Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code su...
vendor_debian·2004·CVSS 10.0
CVE-2004-0889 [CRITICAL] CVE-2004-0889: xpdf - Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code su...
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
Scope: local
bookworm: resolved (fixed in 3.00-10)
bullseye: resolved (fixed in 3.00-10)
forky: resolved (fixed in 3.00-10)
sid: resolved (fixed in 3.00-10)
trixie: resolved (fixed in 3.00-10)
GHSA
GHSA-x479-x3mc-r9mr: Multiple integer overflows in xpdf 2
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2004-0888 [CRITICAL] GHSA-x479-x3mc-r9mr: Multiple integer overflows in xpdf 2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
GHSA
GHSA-xwjm-m85h-4ff8: Multiple integer overflows in xpdf 3
ghsa_unreviewed·2022-04-29·CVSS 10.0
CVE-2004-0889 [CRITICAL] GHSA-xwjm-m85h-4ff8: Multiple integer overflows in xpdf 3
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
OSV
CVE-2004-0889: Multiple integer overflows in xpdf 3
osv·2005-01-27·CVSS 10.0
CVE-2004-0889 [CRITICAL] CVE-2004-0889: Multiple integer overflows in xpdf 3
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
OSV
CVE-2004-0888: Multiple integer overflows in xpdf 2
osv·2005-01-27·CVSS 10.0
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=109880927526773&w=2http://www.gentoo.org/security/en/glsa/glsa-200410-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200410-30.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:113http://www.securityfocus.com/bid/11501https://exchange.xforce.ibmcloud.com/vulnerabilities/17819http://marc.info/?l=bugtraq&m=109880927526773&w=2http://www.gentoo.org/security/en/glsa/glsa-200410-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200410-30.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:113http://www.securityfocus.com/bid/11501https://exchange.xforce.ibmcloud.com/vulnerabilities/17819
2005-01-27
Published