CVE-2005-3628
published 2005-12-31CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.20%
89.8th percentile
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| debian | cups | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | debian_linux | — | — |
| debian | libextractor | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | xpdf | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | xpdf | — | — |
| gnome | gpdf | — | — |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| gnu | libextractor | >= 0 < 0.5.9-1 | 0.5.9-1 |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-1244: xpdf - Unspecified vulnerability in certain versions of xpdf after 3.00, as used in var...
vendor_debian·2006·CVSS 5.0
CVE-2006-1244 [MEDIUM] CVE-2006-1244: xpdf - Unspecified vulnerability in certain versions of xpdf after 3.00, as used in var...
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
security flaw
vendor_redhat·2005-12-06·CVSS 7.5
CVE-2005-3628 [HIGH] security flaw
security flaw
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-3628: cups - Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xp...
vendor_debian·2005·CVSS 7.5
CVE-2005-3628 [HIGH] CVE-2005-3628: cups - Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xp...
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: resolved (fixed in 1.1.22-7)
GHSA
GHSA-c67q-9hxp-64hm: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream
ghsa_unreviewed·2022-05-03
CVE-2005-3628 [HIGH] GHSA-c67q-9hxp-64hm: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
GHSA
GHSA-2hp4-p7vf-34wc: Unspecified vulnerability in certain versions of xpdf after 3
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-1244 [MEDIUM] GHSA-2hp4-p7vf-34wc: Unspecified vulnerability in certain versions of xpdf after 3
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
OSV
CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream
osv·2005-12-31·CVSS 7.5
CVE-2005-3628 [HIGH] CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3628 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-3628 [HIGH] CVE-2005-3628 security flaw
CVE-2005-3628 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Acknowledgments:
Red Hat would like to thank Dirk Mueller for reporting this issue.
Bugzilla
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for xpdf in FC5test2.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
it's fixed in rawhide
Bugzilla
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for poppler (or move to upstream poppler 0.4.4 which
fixes these issues)
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
Rawhide now has poppler-0.5.0 which has fixes for all these issues.
Bugzilla
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2006-01-16·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
A number of issues were found in xpdf. The patch below fixes all the CVE names
above and will be needed for kpdf in kdegraphics.
https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=121940
Discussion:
it's now fixed in kdegraphics-3.5.0-3
Bugzilla
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
bugzilla·2006-01-01·CVSS 5.1
CVE-2005-3191 [MEDIUM] CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
CVE-2005-3191 gpdf multiple issues (CVE-2005-3192 CVE-2005-3196)
The below issues also affect gpdf.
+++ This bug was initially created as a clone of Bug #175404 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5)
Gecko/20051012 Netscape/8.0.4
Description of problem:
05.49.8 CVE: CAN-2005-3191
Platform: Linux
Title: XPDF DCTStream Baseline Remote Heap Buffer Overflow
Description: XPDF is an open source PDF viewer. It is reported prone
to a remote buffer overflow vulnerability in the
"CTStream::readBaselineSOF" function residing in the "xpdf/Stream.cc"
file. This issue is reported to affect XPDF version 3.01. Applications
using embedded XPDF code may be vulnerable to this issue as well.
Ref: http://www.securityfocus.com/bid/15727
Version-Relea
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
Than,
If you can roll up some packages, I'll deal with the errata.
---
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)
bugzilla·2005-12-06·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3628)
+++ This bug was initially created as a clone of Bug #175089 +++
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
-- Additional comment from [email protected] on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek
Discussion:
This issue also affects the tetex for RHEL2.1 and RHEL3
---
Attachment 121940 contains a more complete patch which was taken from our recent
xpdf update.
---
Patches are now applied in RHEL2.1, 3, 4 and packages are built
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
bugzilla·2005-11-22·CVSS 5.1
CVE-2005-3193 [MEDIUM] CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)
Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
This is due to be public 20051201.
An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened.
This issue affects RHEL3, RHEL3, RHEL2.1
Discussion:
Created attachment 121332
Proposed patch from Derek
---
This issue is now public:
http://www.foolabs.com/xpdf/download.html
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
p
ftp://patches.sgi.com/support/free/security/advisories/20060201-01-Uhttp://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlhttp://secunia.com/advisories/18147http://secunia.com/advisories/18380http://secunia.com/advisories/18385http://secunia.com/advisories/18387http://secunia.com/advisories/18389http://secunia.com/advisories/18398http://secunia.com/advisories/18407http://secunia.com/advisories/18416http://secunia.com/advisories/18428http://secunia.com/advisories/18436http://secunia.com/advisories/18534http://secunia.com/advisories/18582http://secunia.com/advisories/18674http://secunia.com/advisories/18675http://secunia.com/advisories/18679http://secunia.com/advisories/18908http://secunia.com/advisories/18913http://secunia.com/advisories/19230http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747http://www.debian.org/security/2005/dsa-931http://www.debian.org/security/2005/dsa-932http://www.debian.org/security/2005/dsa-937http://www.debian.org/security/2005/dsa-938http://www.debian.org/security/2005/dsa-940http://www.debian.org/security/2006/dsa-936http://www.debian.org/security/2006/dsa-950http://www.debian.org/security/2006/dsa-961http://www.debian.org/security/2006/dsa-962http://www.mandriva.com/security/advisories?name=MDKSA-2006:010http://www.mandriva.com/security/advisories?name=MDKSA-2006:011http://www.mandriva.com/security/advisories?name=MDKSA-2006:012http://www.redhat.com/support/errata/RHSA-2006-0160.htmlhttp://www.securityfocus.com/archive/1/427053/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10287ftp://patches.sgi.com/support/free/security/advisories/20060201-01-Uhttp://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlhttp://secunia.com/advisories/18147http://secunia.com/advisories/18380http://secunia.com/advisories/18385http://secunia.com/advisories/18387http://secunia.com/advisories/18389http://secunia.com/advisories/18398http://secunia.com/advisories/18407http://secunia.com/advisories/18416http://secunia.com/advisories/18428http://secunia.com/advisories/18436http://secunia.com/advisories/18534http://secunia.com/advisories/18582http://secunia.com/advisories/18674http://secunia.com/advisories/18675http://secunia.com/advisories/18679http://secunia.com/advisories/18908http://secunia.com/advisories/18913http://secunia.com/advisories/19230http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747http://www.debian.org/security/2005/dsa-931http://www.debian.org/security/2005/dsa-932http://www.debian.org/security/2005/dsa-937http://www.debian.org/security/2005/dsa-938http://www.debian.org/security/2005/dsa-940http://www.debian.org/security/2006/dsa-936http://www.debian.org/security/2006/dsa-950http://www.debian.org/security/2006/dsa-961http://www.debian.org/security/2006/dsa-962http://www.mandriva.com/security/advisories?name=MDKSA-2006:010http://www.mandriva.com/security/advisories?name=MDKSA-2006:011http://www.mandriva.com/security/advisories?name=MDKSA-2006:012http://www.redhat.com/support/errata/RHSA-2006-0160.htmlhttp://www.securityfocus.com/archive/1/427053/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10287
2005-12-31
Published