cbcvebase.
CVE-2005-3628
published 2005-12-31

CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS…

PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.20%
89.8th percentile
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
applecups>= 0 < 1.1.22-71.1.22-7
debiancups< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debiandebian_linux
debianlibextractor< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianxpdf< cups 1.1.22-7 (bookworm)cups 1.1.22-7 (bookworm)
debianxpdf
gnomegpdf
gnulibextractor>= 0 < 0.5.9-10.5.9-1
gnulibextractor>= 0 < 0.5.9-10.5.9-1
gnulibextractor>= 0 < 0.5.9-10.5.9-1
gnulibextractor>= 0 < 0.5.9-10.5.9-1
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
libextractorlibextractor
xpdfxpdf
xpdfxpdf

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.