CVE-2005-3192Improper Restriction of Operations within the Bounds of a Memory Buffer in Xpdf

Severity
7.5HIGHNVD
EPSS
12.3%
top 6.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8
Latest updateMay 3

Description

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

Debianxpdf/xpdf< 3.01-3+3
Debianapple/cups< 1.1.23-13+3
Debiangnu/libextractor< 0.5.8-1+3
Debianfreedesktop/poppler< 0.4.3-2+3
NVDxpdf/xpdf3.0.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xj67-863c-2vj3: Heap-based buffer overflow in the StreamPredictor function in Xpdf 32022-05-03
CVEList
CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 32005-12-08
OSV
CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 32005-12-08

📋Vendor Advisories

3
Ubuntu
xpdf vulnerabilities2005-12-12
Red Hat
security flaw2005-12-06
Debian
CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used...2005

💬Community

26
Bugzilla
CVE-2005-3192 security flaw2018-08-16
Bugzilla
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2006-01-16
Bugzilla
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2006-01-16
Bugzilla
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2006-01-16
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)2006-01-06
CVE-2005-3192 — Xpdf vulnerability | cvebase