CVE-2005-2097
published 2005-08-16CVE-2005-2097: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.43%
34.8th percentile
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| debian | cups | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | libextractor | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | poppler | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | xpdf | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| freedesktop | poppler | >= 0 < 0.4.0-1 | 0.4.0-1 |
| freedesktop | poppler | >= 0 < 0.4.0-1 | 0.4.0-1 |
| freedesktop | poppler | >= 0 < 0.4.0-1 | 0.4.0-1 |
| freedesktop | poppler | >= 0 < 0.4.0-1 | 0.4.0-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 3.00-15 | 3.00-15 |
| xpdf | xpdf | >= 0 < 3.00-15 | 3.00-15 |
| xpdf | xpdf | >= 0 < 3.00-15 | 3.00-15 |
| xpdf | xpdf | >= 0 < 3.00-15 | 3.00-15 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xpdf vulnerability
vendor_ubuntu·2005-08-10
CVE-2005-2097 xpdf vulnerability
Title: xpdf vulnerability
Summary: xpdf vulnerability
xpdf and kpdf did not sufficiently verify the validity of the "loca"
table in PDF files, a table that contains glyph description
information for embedded TrueType fonts. After detecting the broken
table, xpdf attempted to reconstruct the information in it, which
caused the generation of a huge temporary file that quickly filled up
available disk space and rendered the application unresponsive.
The CUPS printing system in Ubuntu 5.04 uses the xpdf-utils package to
convert PDF files to PostScript. By attempting to print such a crafted
PDF file, a remote attacker could cause a Denial of Service in a print
server. The CUPS system in Ubuntu 4.10 is not vulnerable against this
attack.
Instructions: In general, a standard system update wil
Red Hat
security flaw
vendor_redhat·2005-08-09·CVSS 2.1
CVE-2005-2097 [LOW] security flaw
security flaw
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Debian
CVE-2005-2097: cups - xpdf and kpdf do not properly validate the "loca" table in PDF files, which allo...
vendor_debian·2005·CVSS 2.1
CVE-2005-2097 [LOW] CVE-2005-2097: cups - xpdf and kpdf do not properly validate the "loca" table in PDF files, which allo...
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: resolved (fixed in 1.1.22-7)
GHSA
GHSA-x6fq-2ggv-xgcv: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang
ghsa_unreviewed·2022-05-03
CVE-2005-2097 [LOW] GHSA-x6fq-2ggv-xgcv: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
OSV
CVE-2005-2097: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang
osv·2005-08-16·CVSS 2.1
CVE-2005-2097 [LOW] CVE-2005-2097: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2097 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2005-2097 [LOW] CVE-2005-2097 security flaw
CVE-2005-2097 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Bugzilla
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
bugzilla·2006-01-01·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
The below issues also affect gpdf.
+++ This bug was initially created as a clone of Bug #175404 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5)
Gecko/20051012 Netscape/8.0.4
Description of problem:
05.49.8 CVE: CAN-2005-3191
Platform: Linux
Title: XPDF DCTStream Baseline Remote Heap Buffer Overflow
Description: XPDF is an open source PDF viewer. It is reported prone
to a remote buffer overflow vulnerability in the
"CTStream::readBaselineSOF" function residing in the "xpdf/Stream.cc"
file. This issue is reported to affect XPDF version 3.01. Applications
using embedded XPDF code may be vulnerable to this issue as well.
Ref: http://www.securityfocus.com/bid/15727
Version-Relea
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txthttp://secunia.com/advisories/17277http://secunia.com/advisories/18398http://secunia.com/advisories/18407http://secunia.com/advisories/21339http://secunia.com/advisories/25729http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1http://www.debian.org/security/2005/dsa-780http://www.debian.org/security/2006/dsa-1136http://www.debian.org/security/2006/dsa-936http://www.mandriva.com/security/advisories?name=MDKSA-2005:138http://www.novell.com/linux/security/advisories/2005_19_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-670.htmlhttp://www.redhat.com/support/errata/RHSA-2005-671.htmlhttp://www.redhat.com/support/errata/RHSA-2005-706.htmlhttp://www.redhat.com/support/errata/RHSA-2005-708.htmlhttp://www.securityfocus.com/archive/1/427053/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttp://www.securityfocus.com/bid/14529http://www.vupen.com/english/advisories/2007/2280https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10280https://usn.ubuntu.com/163-1/ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txthttp://secunia.com/advisories/17277http://secunia.com/advisories/18398http://secunia.com/advisories/18407http://secunia.com/advisories/21339http://secunia.com/advisories/25729http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1http://www.debian.org/security/2005/dsa-780http://www.debian.org/security/2006/dsa-1136http://www.debian.org/security/2006/dsa-936http://www.mandriva.com/security/advisories?name=MDKSA-2005:138http://www.novell.com/linux/security/advisories/2005_19_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-670.htmlhttp://www.redhat.com/support/errata/RHSA-2005-671.htmlhttp://www.redhat.com/support/errata/RHSA-2005-706.htmlhttp://www.redhat.com/support/errata/RHSA-2005-708.htmlhttp://www.securityfocus.com/archive/1/427053/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttp://www.securityfocus.com/bid/14529http://www.vupen.com/english/advisories/2007/2280https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10280https://usn.ubuntu.com/163-1/
2005-08-16
Published