CVE-2005-3625
published 2005-12-31CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service…
PriorityP426critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.85%
89.0th percentile
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Affected
88 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| conectiva | linux | — | — |
| debian | cups | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libextractor | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | poppler | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | xpdf | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| easy_software_products | cups | — | — |
| freedesktop | poppler | >= 0 < 0.4.4-1 | 0.4.4-1 |
| freedesktop | poppler | >= 0 < 0.4.4-1 | 0.4.4-1 |
| freedesktop | poppler | >= 0 < 0.4.4-1 | 0.4.4-1 |
| freedesktop | poppler | >= 0 < 0.4.4-1 | 0.4.4-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| kde | kdegraphics | — | — |
| kde | kdegraphics | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jm8v-5wvv-cpmw: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service
ghsa_unreviewed·2022-05-03
CVE-2005-3625 [HIGH] GHSA-jm8v-5wvv-cpmw: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
OSV
CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service
osv·2005-12-31·CVSS 10.0
CVE-2005-3625 [CRITICAL] CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Ubuntu
xpdf vulnerabilities in kword, kpdf
vendor_ubuntu·2006-01-09
CVE-2005-3624 xpdf vulnerabilities in kword, kpdf
Title: xpdf vulnerabilities in kword, kpdf
Summary: xpdf vulnerabilities in kword, kpdf
USN-236-1 fixed several vulnerabilities in xpdf. kpdf and kword
contain copies of xpdf code and are thus vulnerable to the same
issues.
For reference, this is the original advisory:
Chris Evans discovered several integer overflows in the XPDF code,
which is present in xpdf, the Poppler library, and tetex-bin. By
tricking an user into opening a specially crafted PDF file, an
attacker could exploit this to execute arbitrary code with the
privileges of the application that processes the document.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
xpdf vulnerabilities
vendor_ubuntu·2006-01-06
CVE-2005-3624 xpdf vulnerabilities
Title: xpdf vulnerabilities
Summary: xpdf vulnerabilities
Chris Evans discovered several integer overflows in the XPDF code,
which is present in xpdf, the Poppler library, and tetex-bin. By
tricking an user into opening a specially crafted PDF file, an
attacker could exploit this to execute arbitrary code with the
privileges of the application that processes the document.
The CUPS printing system also uses XPDF code to convert PDF files to
PostScript. By attempting to print such a crafted PDF file, a remote
attacker could execute arbitrary code with the privileges of the
printer server (user 'cupsys').
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2006-01-03·CVSS 10.0
CVE-2005-3625 [CRITICAL] security flaw
security flaw
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-3625: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l...
vendor_debian·2005·CVSS 10.0
CVE-2005-3625 [CRITICAL] CVE-2005-3625: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l...
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: resolved (fixed in 1.1.22-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3625 security flaw
bugzilla·2018-08-16·CVSS 10.0
CVE-2005-3625 [CRITICAL] CVE-2005-3625 security flaw
CVE-2005-3625 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Acknowledgments:
Red Hat would like to thank Chris Evans for reporting this issue.
Bugzilla
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for xpdf in FC5test2.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
it's fixed in rawhide
Bugzilla
CVE-2005-3624 xpdf issues in tetex for FC5test2 (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 xpdf issues in tetex for FC5test2 (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 xpdf issues in tetex for FC5test2 (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
Since the last update which fixed CVE-2005-3191/2/3, a number of issues were
found in xpdf. The patch below fixes all the CVE names above and will be needed
for tetex in FC5test2. The patch below is for all the issues and includes the
previous CVE-2005-3191/2/3 fixes.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
Oh god, not again... :)
Who should I credit in changelog for this patch?
---
The final patch is from Ludwig Nussel, but was based on so many other fixes I'd
suggest crediting "Ludwig Nussel and others"
---
Applied, thanks.
---
tetex-3.0-10.FC4 has been pushed for fc4, which should resolve this issue. If these problems are still present in this version,
Bugzilla
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for poppler (or move to upstream poppler 0.4.4 which
fixes these issues)
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
Rawhide now has poppler-0.5.0 which has fixes for all these issues.
Bugzilla
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for kpdf in kdegraphics.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
it's now fixed in kdegraphics-3.5.0-3
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-06·CVSS 5.1
CVE-2005-3624 [MEDIUM] [RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-01
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-06·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
From User-Agent: XML-RPC
poppler-0.4.4-1.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
Closing bugs in MODIFIED state from prior Fedora releases. If this bug persists
in a current Fedora release (such as Fedora Core 5 or later), please reopen and
set the version appropriately.
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Our fix for RHEL contained these fixes, but our xpdf update for Fedora does not.
Discussion:
These issues also affect FC3 and FC5
---
it's already fixed in 3.01-0.FC3.4 (FC3), 3.01-0.FC4.6 (FC4) and 3.01-7(FC5).
Bugzilla
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
This issue also affects RHEL3
---
Fixed in devel.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work f
Bugzilla
[FC3] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] [FC3] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[FC3] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
From User-Agent: XML-RPC
gpdf-2.8.2-7.2 has been pushed for FC3, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
Fedora Core 3 is now maintained by the Fedora Legacy project for security
updates only. If this problem is a security issue, please reopen and
reassign to the Fedora Lega
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] [RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0177.html
Bugzilla
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
bugzilla·2006-01-01·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
The below issues also affect gpdf.
+++ This bug was initially created as a clone of Bug #175404 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5)
Gecko/20051012 Netscape/8.0.4
Description of problem:
05.49.8 CVE: CAN-2005-3191
Platform: Linux
Title: XPDF DCTStream Baseline Remote Heap Buffer Overflow
Description: XPDF is an open source PDF viewer. It is reported prone
to a remote buffer overflow vulnerability in the
"CTStream::readBaselineSOF" function residing in the "xpdf/Stream.cc"
file. This issue is reported to affect XPDF version 3.01. Applications
using embedded XPDF code may be vulnerable to this issue as well.
Ref: http://www.securityfocus.com/bid/15727
Version-Relea
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
Than,
If you can roll up some packages, I'll deal with the errata.
---
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2005-11-22·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
Discussion:
Created attachment 121332
Proposed patch from Derek
---
This issue is now public:
http://www.foolabs.com/xpdf/download.html
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
p
Bugzilla
KOffice multiple vulnerabilities (CAN-2005-2971, CAN-2005-3191, CVE-2005-3192, CAN-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627)
bugzilla·2005-01-10·CVSS 7.5
CVE-2005-3192 [HIGH] KOffice multiple vulnerabilities (CAN-2005-2971, CAN-2005-3191, CVE-2005-3192, CAN-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627)
KOffice multiple vulnerabilities (CAN-2005-2971, CAN-2005-3191, CVE-2005-3192, CAN-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627)
according to http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:165
, koffice also includes the buggy xpdf code vulnerable to CAN-2004-0888,0889,1125.
------- Bug moved to this database by [email protected] 2005-03-30 18:30 -------
This bug previously known as bug 2372 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2372
Originally filed under the Fedora Legacy product and General component.
Unknown priority P2. Setting to default priority "normal".
Unknown platform PC. Setting to default platform "All".
The original reporter of this bug does not have
an account here. Reassigning to the person who
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txtftp://patches.sgi.com/support/free/security/advisories/20051201-01-Uftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uftp://patches.sgi.com/support/free/security/advisories/20060201-01-Uhttp://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0177.htmlhttp://scary.beasts.org/security/CESA-2005-003.txthttp://secunia.com/advisories/18147http://secunia.com/advisories/18303http://secunia.com/advisories/18312http://secunia.com/advisories/18313http://secunia.com/advisories/18329http://secunia.com/advisories/18332http://secunia.com/advisories/18334http://secunia.com/advisories/18335http://secunia.com/advisories/18338http://secunia.com/advisories/18349http://secunia.com/advisories/18373http://secunia.com/advisories/18375http://secunia.com/advisories/18380http://secunia.com/advisories/18385http://secunia.com/advisories/18387http://secunia.com/advisories/18389http://secunia.com/advisories/18398http://secunia.com/advisories/18407http://secunia.com/advisories/18414http://secunia.com/advisories/18416http://secunia.com/advisories/18423http://secunia.com/advisories/18425http://secunia.com/advisories/18428http://secunia.com/advisories/18436http://secunia.com/advisories/18448http://secunia.com/advisories/18463http://secunia.com/advisories/18517http://secunia.com/advisories/18534http://secunia.com/advisories/18554http://secunia.com/advisories/18582http://secunia.com/advisories/18642http://secunia.com/advisories/18644http://secunia.com/advisories/18674http://secunia.com/advisories/18675http://secunia.com/advisories/18679http://secunia.com/advisories/18908http://secunia.com/advisories/18913http://secunia.com/advisories/19230http://secunia.com/advisories/19377http://secunia.com/advisories/25729http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1http://www.debian.org/security/2005/dsa-931http://www.debian.org/security/2005/dsa-932http://www.debian.org/security/2005/dsa-937http://www.debian.org/security/2005/dsa-938http://www.debian.org/security/2005/dsa-940http://www.debian.org/security/2006/dsa-936http://www.debian.org/security/2006/dsa-950http://www.debian.org/security/2006/dsa-961http://www.debian.org/security/2006/dsa-962http://www.gentoo.org/security/en/glsa/glsa-200601-02.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200601-17.xmlhttp://www.kde.org/info/security/advisory-20051207-2.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2006:003http://www.mandriva.com/security/advisories?name=MDKSA-2006:004http://www.mandriva.com/security/advisories?name=MDKSA-2006:005http://www.mandriva.com/security/advisories?name=MDKSA-2006:006http://www.mandriva.com/security/advisories?name=MDKSA-2006:008http://www.mandriva.com/security/advisories?name=MDKSA-2006:010http://www.mandriva.com/security/advisories?name=MDKSA-2006:011http://www.mandriva.com/security/advisories?name=MDKSA-2006:012http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00010.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00011.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00030.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00031.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0160.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0163.htmlhttp://www.securityfocus.com/archive/1/427053/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttp://www.securityfocus.com/bid/16143http://www.trustix.org/errata/2006/0002/http://www.vupen.com/english/advisories/2006/0047http://www.vupen.com/english/advisories/2007/2280https://exchange.xforce.ibmcloud.com/vulnerabilities/24023https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9575https://usn.ubuntu.com/236-1/ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txtftp://patches.sgi.com/support/free/security/advisories/20051201-01-Uftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uftp://patches.sgi.com/support/free/security/advisories/20060201-01-Uhttp://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0177.htmlhttp://scary.beasts.org/security/CESA-2005-003.txthttp://secunia.com/advisories/18147http://secunia.com/advisories/18303http://secunia.com/advisories/18312http://secunia.com/advisories/18313http://secunia.com/advisories/18329http://secunia.com/advisories/18332http://secunia.com/advisories/18334http://secunia.com/advisories/18335
+ 70 more references
2005-12-31
Published