CVE-2005-0206

10 documents7 sources
Severity
7.5HIGH
EPSS
6.5%
top 8.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 1

Description

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages19 packages

NVDxpdf/xpdf11 versions+10
NVDredhat/linux9.0
NVDsuse/suse_linux27 versions+26

Also affects: Debian Linux 3.0, Ubuntu Linux 4.1, Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jp38-q8w6-3xm3: The patch for integer overflow vulnerabilities in Xpdf 22022-05-01
OSV
CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 22005-04-27
CVEList
CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 22005-02-15

📋Vendor Advisories

3
Red Hat
cups: incomplete fix for CVE-2004-0888 / CVE-2005-02062008-04-01
Debian
CVE-2005-0206: cups - The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-088...2005
Red Hat
security flaw2004-10-20

💬Community

3
Bugzilla
CVE-2005-0206 security flaw2018-08-16
Bugzilla
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-02062008-03-20
Bugzilla
CAN-2004-0888 xpdf issues affect cups (CAN-2005-0206)2005-02-08