cbcvebase.
CVE-2005-2097
published 2005-08-16

CVE-2005-2097: xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a…

PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.43%
34.8th percentile
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.

Affected

23 ranges
VendorProductVersion rangeFixed in
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
debiancups< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianlibextractor< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianpoppler< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianxpdf< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
freedesktoppoppler>= 0 < 0.4.0-10.4.0-1
freedesktoppoppler>= 0 < 0.4.0-10.4.0-1
freedesktoppoppler>= 0 < 0.4.0-10.4.0-1
freedesktoppoppler>= 0 < 0.4.0-10.4.0-1
gnulibextractor>= 0 < 0.5.8-10.5.8-1
gnulibextractor>= 0 < 0.5.8-10.5.8-1
gnulibextractor>= 0 < 0.5.8-10.5.8-1
gnulibextractor>= 0 < 0.5.8-10.5.8-1
xpdfxpdf
xpdfxpdf
xpdfxpdf
xpdfxpdf>= 0 < 3.00-153.00-15
xpdfxpdf>= 0 < 3.00-153.00-15
xpdfxpdf>= 0 < 3.00-153.00-15
xpdfxpdf>= 0 < 3.00-153.00-15

CVSS provenance

nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.