CVE-2005-3628Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Cups

13 documents7 sources
Severity
7.5HIGHNVD
EPSS
2.7%
top 14.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateMay 3

Description

Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Debianxpdf/xpdf< 3.01-4+3
Debianapple/cups< 1.1.22-7+3
Debiangnu/libextractor< 0.5.9-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c67q-9hxp-64hm: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream2022-05-03
CVEList
CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream2006-01-23
OSV
CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream2005-12-31

📋Vendor Advisories

2
Red Hat
security flaw2005-12-06
Debian
CVE-2005-3628: cups - Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xp...2005

💬Community

7
Bugzilla
CVE-2005-3628 security flaw2018-08-16
Bugzilla
CVE-2005-3191 xpdf issues in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2006-01-16
Bugzilla
CVE-2005-3191 xpdf issues affect poppler in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2006-01-16
Bugzilla
CVE-2005-3191 xpdf issues affect kdegraphics in FC5test2 (CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2006-01-16
Bugzilla
CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628)2005-12-06
CVE-2005-3628 — Apple Cups vulnerability | cvebase