CVE-2004-1125
published 2005-01-10CVE-2004-1125: Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and…
PriorityP432critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.58%
93.1th percentile
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| apple | cups | >= 0 < 1.1.22-2 | 1.1.22-2 |
| debian | cups | < cups 1.1.22-2 (bookworm) | cups 1.1.22-2 (bookworm) |
| debian | xpdf | < cups 1.1.22-2 (bookworm) | cups 1.1.22-2 (bookworm) |
| easy_software_products | cups | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 3.00-11 | 3.00-11 |
| xpdf | xpdf | >= 0 < 3.00-11 | 3.00-11 |
| xpdf | xpdf | >= 0 < 3.00-11 | 3.00-11 |
| xpdf | xpdf | >= 0 < 3.00-11 | 3.00-11 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-68gp-v694-mxpq: Buffer overflow in the Gfx::doImage function in Gfx
ghsa_unreviewed·2022-05-03
CVE-2004-1125 [HIGH] CWE-20 GHSA-68gp-v694-mxpq: Buffer overflow in the Gfx::doImage function in Gfx
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
OSV
CVE-2004-1125: Buffer overflow in the Gfx::doImage function in Gfx
osv·2005-01-10·CVSS 9.3
CVE-2004-1125 [CRITICAL] CVE-2004-1125: Buffer overflow in the Gfx::doImage function in Gfx
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
Ubuntu
xpdf, tetex-bin vulnerabilities
vendor_ubuntu·2004-12-23
CVE-2004-1125 xpdf, tetex-bin vulnerabilities
Title: xpdf, tetex-bin vulnerabilities
Summary: xpdf, tetex-bin vulnerabilities
A potential buffer overflow has been found in the xpdf viewer. An
insufficient input validation could be exploited by an attacker
providing a specially crafted PDF file which, when processed by xpdf,
could result in abnormal program termination or the execution of
attacker supplied program code with the user's privileges.
The tetex-bin package contains the affected xpdf code to generate PDF
output and process included PDF files, thus is vulnerable as well.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2004-12-23
CVE-2004-1125 CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: CUPS vulnerabilities
CAN-2004-1125:
The recent USN-48-1 fixed a buffer overflow in xpdf. Since CUPS
contains xpdf code to convert incoming PDF files to the PostScript
format, this vulnerability applies to cups as well.
In this case it could even lead to privilege escalation: if an
attacker submitted a malicious PDF file for printing, he could be
able to execute arbitrary commands with the privileges of the
CUPS server.
Please note that the Ubuntu version of CUPS runs as a minimally
privileged user 'cupsys' by default, so there is no possibility of
root privilege escalation. The privileges of the 'cupsys' user are
confined to modifying printer configurations, altering print jobs,
and controlling printers.
CAN-2004-1267:
Ariel Berkman discovered a
Red Hat
security flaw
vendor_redhat·2004-12-21·CVSS 9.3
CVE-2004-1125 [CRITICAL] security flaw
security flaw
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
Debian
CVE-2004-1125: cups - Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other ...
vendor_debian·2004·CVSS 9.3
CVE-2004-1125 [CRITICAL] CVE-2004-1125: cups - Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other ...
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
Scope: local
bookworm: resolved (fixed in 1.1.22-2)
bullseye: resolved (fixed in 1.1.22-2)
forky: resolved (fixed in 1.1.22-2)
sid: resolved (fixed in 1.1.22-2)
trixie: resolved (fixed in 1.1.22-2)
No detection rules found.
No public exploits indexed.
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl2.patchftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000921http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030241.htmlhttp://marc.info/?t=110378596500001&r=1&w=2http://secunia.com/advisories/17277http://securitytracker.com/id?1012646http://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200501-13.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200501-17.xmlhttp://www.idefense.com/application/poi/display?id=172&type=vulnerabilitieshttp://www.kde.org/info/security/advisory-20041223-1.txthttp://www.novell.com/linux/security/advisories/2005_01_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-018.htmlhttp://www.redhat.com/support/errata/RHSA-2005-026.htmlhttp://www.redhat.com/support/errata/RHSA-2005-034.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttp://www.redhat.com/support/errata/RHSA-2005-057.htmlhttp://www.redhat.com/support/errata/RHSA-2005-066.htmlhttp://www.redhat.com/support/errata/RHSA-2005-354.htmlhttp://www.securityfocus.com/bid/12070https://bugzilla.fedora.us/show_bug.cgi?id=2352https://bugzilla.fedora.us/show_bug.cgi?id=2353https://exchange.xforce.ibmcloud.com/vulnerabilities/18641https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10830https://usn.ubuntu.com/50-1/ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl2.patchftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000921http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030241.htmlhttp://marc.info/?t=110378596500001&r=1&w=2http://secunia.com/advisories/17277http://securitytracker.com/id?1012646http://www.gentoo.org/security/en/glsa/glsa-200412-25.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200501-13.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200501-17.xmlhttp://www.idefense.com/application/poi/display?id=172&type=vulnerabilitieshttp://www.kde.org/info/security/advisory-20041223-1.txthttp://www.novell.com/linux/security/advisories/2005_01_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-013.htmlhttp://www.redhat.com/support/errata/RHSA-2005-018.htmlhttp://www.redhat.com/support/errata/RHSA-2005-026.htmlhttp://www.redhat.com/support/errata/RHSA-2005-034.htmlhttp://www.redhat.com/support/errata/RHSA-2005-053.htmlhttp://www.redhat.com/support/errata/RHSA-2005-057.htmlhttp://www.redhat.com/support/errata/RHSA-2005-066.htmlhttp://www.redhat.com/support/errata/RHSA-2005-354.htmlhttp://www.securityfocus.com/bid/12070https://bugzilla.fedora.us/show_bug.cgi?id=2352https://bugzilla.fedora.us/show_bug.cgi?id=2353https://exchange.xforce.ibmcloud.com/vulnerabilities/18641https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10830https://usn.ubuntu.com/50-1/
2005-01-10
Published