cbcvebase.
CVE-2005-3624
published 2005-12-31

CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to…

medium5CVSS 3.1
AVNACLAuNCNIPAN
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.

Affected

114 ranges· showing 25
VendorProductVersion rangeFixed in
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
conectivalinux
debiancups< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debiandebian_linux
debiandebian_linux
debianlibextractor< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianpoppler< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianxpdf< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianxpdf
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
freedesktoppoppler>= 0 < 0.4.4-10.4.4-1
freedesktoppoppler>= 0 < 0.4.4-10.4.4-1
freedesktoppoppler>= 0 < 0.4.4-10.4.4-1
freedesktoppoppler>= 0 < 0.4.4-10.4.4-1
gnomegpdf
gnulibextractor>= 0 < 0.5.9-10.5.9-1
gnulibextractor>= 0 < 0.5.9-10.5.9-1
gnulibextractor>= 0 < 0.5.9-10.5.9-1
gnulibextractor>= 0 < 0.5.9-10.5.9-1

CVSS provenance

nvd7.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv5.0MEDIUM