CVE-2005-3192
published 2005-12-08CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.14%
92.7th percentile
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.23-13 | 1.1.23-13 |
| apple | cups | >= 0 < 1.1.23-13 | 1.1.23-13 |
| apple | cups | >= 0 < 1.1.23-13 | 1.1.23-13 |
| apple | cups | >= 0 < 1.1.23-13 | 1.1.23-13 |
| debian | cups | < cups 1.1.23-13 (bookworm) | cups 1.1.23-13 (bookworm) |
| debian | libextractor | < cups 1.1.23-13 (bookworm) | cups 1.1.23-13 (bookworm) |
| debian | poppler | < cups 1.1.23-13 (bookworm) | cups 1.1.23-13 (bookworm) |
| debian | xpdf | < cups 1.1.23-13 (bookworm) | cups 1.1.23-13 (bookworm) |
| freedesktop | poppler | >= 0 < 0.4.3-2 | 0.4.3-2 |
| freedesktop | poppler | >= 0 < 0.4.3-2 | 0.4.3-2 |
| freedesktop | poppler | >= 0 < 0.4.3-2 | 0.4.3-2 |
| freedesktop | poppler | >= 0 < 0.4.3-2 | 0.4.3-2 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| gnu | libextractor | >= 0 < 0.5.8-1 | 0.5.8-1 |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 3.01-3 | 3.01-3 |
| xpdf | xpdf | >= 0 < 3.01-3 | 3.01-3 |
| xpdf | xpdf | >= 0 < 3.01-3 | 3.01-3 |
| xpdf | xpdf | >= 0 < 3.01-3 | 3.01-3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xpdf vulnerabilities
vendor_ubuntu·2005-12-12
CVE-2005-3191 xpdf vulnerabilities
Title: xpdf vulnerabilities
Summary: xpdf vulnerabilities
infamous41md discovered several integer overflows in the XPDF code,
which is present in xpdf, the Poppler library, tetex-bin, KOffice, and
kpdf. By tricking an user into opening a specially crafted PDF file,
an attacker could exploit this to execute arbitrary code with the
privileges of the application that processes the document.
The CUPS printing system also uses XPDF code to convert PDF files to
PostScript. By attempting to print such a crafted PDF file, a remote
attacker could execute arbitrary code with the privileges of the
printer server (user 'cupsys').
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-12-06·CVSS 7.5
CVE-2005-3192 [HIGH] security flaw
security flaw
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used...
vendor_debian·2005·CVSS 7.5
CVE-2005-3192 [HIGH] CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used...
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Scope: local
bookworm: resolved (fixed in 1.1.23-13)
bullseye: resolved (fixed in 1.1.23-13)
forky: resolved (fixed in 1.1.23-13)
sid: resolved (fixed in 1.1.23-13)
trixie: resolved (fixed in 1.1.23-13)
GHSA
GHSA-xj67-863c-2vj3: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3
ghsa_unreviewed·2022-05-03
CVE-2005-3192 [HIGH] CWE-119 GHSA-xj67-863c-2vj3: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
OSV
CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3
osv·2005-12-08·CVSS 7.5
CVE-2005-3192 [HIGH] CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3192 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-3192 [HIGH] CVE-2005-3192 security flaw
CVE-2005-3192 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Acknowledgments:
Red Hat would like to thank Derek B. Noonburg for reporting this issue and providing a patch.
Bugzilla
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for xpdf in FC5test2.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
it's fixed in rawhide
Bugzilla
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for poppler (or move to upstream poppler 0.4.4 which
fixes these issues)
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
Rawhide now has poppler-0.5.0 which has fixes for all these issues.
Bugzilla
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for kpdf in kdegraphics.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
it's now fixed in kdegraphics-3.5.0-3
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-06·CVSS 5.1
CVE-2005-3624 [MEDIUM] [RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-01
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-06·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
From User-Agent: XML-RPC
poppler-0.4.4-1.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
Closing bugs in MODIFIED state from prior Fedora releases. If this bug persists
in a current Fedora release (such as Fedora Core 5 or later), please reopen and
set the version appropriately.
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Our fix for RHEL contained these fixes, but our xpdf update for Fedora does not.
Discussion:
These issues also affect FC3 and FC5
---
it's already fixed in 3.01-0.FC3.4 (FC3), 3.01-0.FC4.6 (FC4) and 3.01-7(FC5).
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
This issue also affects RHEL3
---
Fixed in devel.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work f
Bugzilla
[FC3] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] [FC3] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[FC3] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
From User-Agent: XML-RPC
gpdf-2.8.2-7.2 has been pushed for FC3, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
Fedora Core 3 is now maintained by the Fedora Legacy project for security
updates only. If this problem is a security issue, please reopen and
reassign to the Fedora Lega
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] [RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0177.html
Bugzilla
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
bugzilla·2006-01-01·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
The below issues also affect gpdf.
+++ This bug was initially created as a clone of Bug #175404 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5)
Gecko/20051012 Netscape/8.0.4
Description of problem:
05.49.8 CVE: CAN-2005-3191
Platform: Linux
Title: XPDF DCTStream Baseline Remote Heap Buffer Overflow
Description: XPDF is an open source PDF viewer. It is reported prone
to a remote buffer overflow vulnerability in the
"CTStream::readBaselineSOF" function residing in the "xpdf/Stream.cc"
file. This issue is reported to affect XPDF version 3.01. Applications
using embedded XPDF code may be vulnerable to this issue as well.
Ref: http://www.securityfocus.com/bid/15727
Version-Relea
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-13·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #173888 +++
Numerous issue have been discovered in xpdf (which cups contains the source for)
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue should also affect RHEL3
I will attach a patch as soon as we have a complete one.
Discussion:
The patches for these issues are in attachment 122226 and attachment 122227.
The sooner we can have new packages rolled the better as the Christmas holiday
is quickly approaching.
---
Do we have an RHTS test case for this?
---
There aren't currently any reproducers for these issues.
Please note that these issues affect xpdf, kdegraphics, cups
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-13·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #175645 +++
Numerous issue have been discovered in xpdf (which cups contains the source for)
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue should also affect FC3
I will attach a patch as soon as we have a complete one.
Discussion:
The patches for these issues are in attachment 122226 and attachment 122227.
The sooner we can have new packages rolled the better as the Christmas holiday
is quickly approaching.
---
There aren't currently any reproducers for these issues.
Please note that these issues affect xpdf, kdegraphics, cups, gpdf, tetex and
poppler. Some cooperation wil
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #173888 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
---
From User-Agent: XML-RPC
poppler-0.4.1-1.2 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of i
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #175105 +++
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
This issue also affects FC3
Discussion:
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
---
The patches for these issues are in attachm
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
Than,
If you can roll up some packages, I'll deal with the errata.
---
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
This issue also affects the tetex for RHEL2.1 and RHEL3
---
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
---
Patches are now applied in RHEL2.1, 3, 4 and packages are built
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #175100 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
---
The patches for these issues are in attachment 122226 and attachment 122227.
The sooner we can have new packages rolled the better as the
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #173888 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
These issues have been fixed in FEDORA-2005-1121 and FEDORA-2005-1122.
---
The original fix for this issue was incomplete.
---
The patches for these issues are in attachment 122226 and attachment 122227.
The sooner we can have new pac
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #175109 +++
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
This issue also affects FC3
Discussion:
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
---
Applied in FC3 and FC4. Packages are now built.
---
From User-Agent: XML-RPC
tetex
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
+++ This bug was initially created as a clone of Bug #173888 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
Ray,
If you can roll some new packages and let me know the n-v-r, I'll take care of
the errata.
---
Created attachment 121940
More complete patch taken from our xpdf update
---
An advisory has been issued which should help the problem
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2005-11-22·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
Discussion:
Created attachment 121332
Proposed patch from Derek
---
This issue is now public:
http://www.foolabs.com/xpdf/download.html
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
p
Bugzilla
KOffice multiple vulnerabilities (CAN-2005-2971, CAN-2005-3191, CVE-2005-3192, CAN-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627)
bugzilla·2005-01-10·CVSS 7.5
CVE-2005-3192 [HIGH] KOffice multiple vulnerabilities (CAN-2005-2971, CAN-2005-3191, CVE-2005-3192, CAN-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627)
KOffice multiple vulnerabilities (CAN-2005-2971, CAN-2005-3191, CVE-2005-3192, CAN-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627)
according to http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:165
, koffice also includes the buggy xpdf code vulnerable to CAN-2004-0888,0889,1125.
------- Bug moved to this database by [email protected] 2005-03-30 18:30 -------
This bug previously known as bug 2372 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2372
Originally filed under the Fedora Legacy product and General component.
Unknown priority P2. Setting to default priority "normal".
Unknown platform PC. Setting to default platform "All".
The original reporter of this bug does not have
an account here. Reassigning to the person who
Bugzilla
xpdf code in pdflatex is exploitable, CAN-2004-1125, CAN-2005-0064, CAN-2004-0888, CVE-2005-3191, CVE-2005-3192, CVE-2005-3193
bugzilla·2004-12-08·CVSS 5.1
CVE-2005-3191 [MEDIUM] xpdf code in pdflatex is exploitable, CAN-2004-1125, CAN-2005-0064, CAN-2004-0888, CVE-2005-3191, CVE-2005-3192, CVE-2005-3193
xpdf code in pdflatex is exploitable, CAN-2004-1125, CAN-2005-0064, CAN-2004-0888, CVE-2005-3191, CVE-2005-3192, CVE-2005-3193
according to Ubuntu Security Notice USN-9-1, pdflatex has the same vulnerable
code from xpdf that was described in CAN-2004-0888.
i assume the version shipped with rh73 and others is vulnerable?
===
[beej@tenet beej]$ rpm -qf /usr/bin/pdflatex
tetex-latex-1.0.7-47
===
------- Additional Comments From [email protected] 2005-01-04 05:17:37 ----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
here are updated packages to QA for fc1:
- - patches from FC-2 fix CAN-2004-0888, CAN-2004-1125
- - rpm-build-compare.sh shows lots of differences. i hope they
are negligible but someone should look closely at them.
- - it seems exceedingly ugly to have the package a
arXiv
DAG-Based Attack and Defense Modeling: Don't Miss the Forest for the Attack Trees
arxiv_fulltext·2013-03-29
DAG-Based Attack and Defense Modeling: Don't Miss the Forest for the Attack Trees
## Abstract
This paper presents the current state of the art on attack and defense
modeling approaches that are based on directed acyclic graphs (DAGs). DAGs
allow for a hierarchical decomposition of complex scenarios into simple, easily
understandable and quantifiable actions. Methods based on threat trees and
Bayesian networks are two well-known approaches to security modeling. However
there exist more than 30 DAG-based methodologies, each having different
features and goals. The objective of this survey is to present a complete
overview of graphical attack and defense modeling techniques based on DAGs.
This consists of summarizing the existing methodologies, comparing their
features and proposing a taxonomy of the described formalisms. This article
also supports the selection of an ade
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.01pl1.patchftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txtftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.20/SCOSA-2006.20.txtftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.21/SCOSA-2006.21.txtftp://patches.sgi.com/support/free/security/advisories/20051201-01-Uftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uftp://patches.sgi.com/support/free/security/advisories/20060201-01-Uhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=342289http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlhttp://rhn.redhat.com/errata/RHSA-2005-868.htmlhttp://scary.beasts.org/security/CESA-2005-003.txthttp://secunia.com/advisories/17897/http://secunia.com/advisories/17908http://secunia.com/advisories/17912http://secunia.com/advisories/17916http://secunia.com/advisories/17920http://secunia.com/advisories/17921http://secunia.com/advisories/17926http://secunia.com/advisories/17929http://secunia.com/advisories/17940http://secunia.com/advisories/17955http://secunia.com/advisories/17976http://secunia.com/advisories/18009http://secunia.com/advisories/18055http://secunia.com/advisories/18061http://secunia.com/advisories/18189http://secunia.com/advisories/18191http://secunia.com/advisories/18192http://secunia.com/advisories/18303http://secunia.com/advisories/18313http://secunia.com/advisories/18336http://secunia.com/advisories/18349http://secunia.com/advisories/18380http://secunia.com/advisories/18385http://secunia.com/advisories/18387http://secunia.com/advisories/18389http://secunia.com/advisories/18398http://secunia.com/advisories/18407http://secunia.com/advisories/18416http://secunia.com/advisories/18428http://secunia.com/advisories/18436http://secunia.com/advisories/18448http://secunia.com/advisories/18503http://secunia.com/advisories/18517http://secunia.com/advisories/18534http://secunia.com/advisories/18549http://secunia.com/advisories/18554http://secunia.com/advisories/18582http://secunia.com/advisories/18674http://secunia.com/advisories/18675http://secunia.com/advisories/18679http://secunia.com/advisories/18908http://secunia.com/advisories/18913http://secunia.com/advisories/19230http://secunia.com/advisories/19377http://secunia.com/advisories/19797http://secunia.com/advisories/19798http://secunia.com/advisories/25729http://secunia.com/advisories/26413http://securityreason.com/securityalert/235http://securityreason.com/securityalert/240http://securitytracker.com/id?1015309http://securitytracker.com/id?1015324http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1http://www.debian.org/security/2005/dsa-931http://www.debian.org/security/2005/dsa-932http://www.debian.org/security/2006/dsa-936http://www.debian.org/security/2006/dsa-937http://www.debian.org/security/2006/dsa-950http://www.debian.org/security/2006/dsa-961http://www.debian.org/security/2006/dsa-962http://www.gentoo.org/security/en/glsa/glsa-200512-08.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200601-02.xmlhttp://www.idefense.com/application/poi/display?id=344&type=vulnerabilitieshttp://www.kde.org/info/security/advisory-20051207-1.txthttp://www.kde.org/info/security/advisory-20051207-2.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2006:003http://www.mandriva.com/security/advisories?name=MDKSA-2006:004http://www.mandriva.com/security/advisories?name=MDKSA-2006:005http://www.mandriva.com/security/advisories?name=MDKSA-2006:006http://www.mandriva.com/security/advisories?name=MDKSA-2006:008http://www.mandriva.com/security/advisories?name=MDKSA-2006:010http://www.mandriva.com/security/advisories?name=MDKSA-2006:011http://www.novell.com/linux/security/advisories/2005_29_sr.htmlhttp://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-December/msg00015.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-December/msg00016.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-December/msg00036.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-December/msg00037.htmlhttp://www.redhat.com/support/errata/RHSA-2005-840.htmlhttp://www.redhat.com/support/errata/RHSA-2005-867.htmlhttp://www.redhat.com/support/errata/RHSA-2005-878.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0160.htmlhttp://www.securityfocus.com/archive/1/418883/100/0/threadedhttp://www.securityfocus.com/archive/1/427053/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttp://www.securityfocus.com/bid/15725http://www.trustix.org/errata/2005/0072/
+ 124 more references
2005-12-08
Published