CVE-2006-0301
published 2006-01-30CVE-2006-0301: Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.51%
90.5th percentile
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libextractor | < libextractor 0.5.10-1 (bookworm) | libextractor 0.5.10-1 (bookworm) |
| debian | poppler | < libextractor 0.5.10-1 (bookworm) | libextractor 0.5.10-1 (bookworm) |
| debian | xpdf | < libextractor 0.5.10-1 (bookworm) | libextractor 0.5.10-1 (bookworm) |
| debian | xpdf | — | — |
| freedesktop | poppler | >= 0 < 0.4.5-1 | 0.4.5-1 |
| freedesktop | poppler | >= 0 < 0.4.5-1 | 0.4.5-1 |
| freedesktop | poppler | >= 0 < 0.4.5-1 | 0.4.5-1 |
| freedesktop | poppler | >= 0 < 0.4.5-1 | 0.4.5-1 |
| gnome | gpdf | — | — |
| gnu | libextractor | >= 0 < 0.5.10-1 | 0.5.10-1 |
| gnu | libextractor | >= 0 < 0.5.10-1 | 0.5.10-1 |
| gnu | libextractor | >= 0 < 0.5.10-1 | 0.5.10-1 |
| gnu | libextractor | >= 0 < 0.5.10-1 | 0.5.10-1 |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xpdf/poppler/kpdf vulnerabilities
vendor_ubuntu·2006-02-15
CVE-2006-0301 xpdf/poppler/kpdf vulnerabilities
Title: xpdf/poppler/kpdf vulnerabilities
Summary: xpdf/poppler/kpdf vulnerabilities
The splash image handler in xpdf did not check the validity of
coordinates. By tricking a user into opening a specially crafted PDF
file, an attacker could exploit this to trigger a buffer overflow
which could lead to arbitrary code execution with the privileges of
the user.
The poppler library and kpdf also contain xpdf code, and thus are
affected by the same vulnerability.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2006-01-05·CVSS 7.5
CVE-2006-0301 [HIGH] security flaw
security flaw
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Debian
CVE-2006-0301: libextractor - Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such ...
vendor_debian·2006·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301: libextractor - Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such ...
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Scope: local
bookworm: resolved (fixed in 0.5.10-1)
bullseye: resolved (fixed in 0.5.10-1)
forky: resolved (fixed in 0.5.10-1)
sid: resolved (fixed in 0.5.10-1)
trixie: resolved (fixed in 0.5.10-1)
Debian
CVE-2006-1244: xpdf - Unspecified vulnerability in certain versions of xpdf after 3.00, as used in var...
vendor_debian·2006·CVSS 5.0
CVE-2006-1244 [MEDIUM] CVE-2006-1244: xpdf - Unspecified vulnerability in certain versions of xpdf after 3.00, as used in var...
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-rj3h-g34f-3227: Heap-based buffer overflow in Splash
ghsa_unreviewed·2022-05-03
CVE-2006-0301 [HIGH] CWE-119 GHSA-rj3h-g34f-3227: Heap-based buffer overflow in Splash
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
GHSA
GHSA-2hp4-p7vf-34wc: Unspecified vulnerability in certain versions of xpdf after 3
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-1244 [MEDIUM] GHSA-2hp4-p7vf-34wc: Unspecified vulnerability in certain versions of xpdf after 3
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
OSV
CVE-2006-0301: Heap-based buffer overflow in Splash
osv·2006-01-30·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301: Heap-based buffer overflow in Splash
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-0301 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 security flaw
CVE-2006-0301 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Bugzilla
Multiple KDE package tracker for multiple vulnerabilities
bugzilla·2006-02-03·CVSS 7.5
CVE-2006-0019 [HIGH] Multiple KDE package tracker for multiple vulnerabilities
Multiple KDE package tracker for multiple vulnerabilities
This bug ticket is being created to be a package tracker for multiple
security bugs identified in KDE from a list in Attachment 123541 for Fedora
Legacy-maintained distros. Please add bugs to the "depends on" list as new
packages are identified which need patching from the Febr. 2005 last set of
Legacy packages up through CVE-2006-0019.
Thanks.
Discussion:
Bug 178606 is for the kdelibs package.
---
Created attachment 124082
Partially filled-out spreadsheet for vulnerabilities vs. distros
Attached is a spreadsheet I have partly completed in discerning which KDE
packages and which distros are affected by which vulnerability from the list
in attachment 123541.
---
Created attachment 124098
Completed spreadsheet - KDE vulnerabi
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow (FC5test2)
bugzilla·2006-01-31·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow (FC5test2)
CVE-2006-0301 PDF splash handling heap overflow (FC5test2)
+++ This bug was initially created as a clone of Bug #179056 +++
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
The proposed patch is attachment 123745
Discussion:
ping! if fixed in rawhide please close this bug, otherwise please try to fix
this before FC5Test3 (Feb 13)
---
it's now fixed in rawhide
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow (FC5test2)
bugzilla·2006-01-31·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow (FC5test2)
CVE-2006-0301 PDF splash handling heap overflow (FC5test2)
+++ This bug was initially created as a clone of Bug #179047 +++
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
-- Additional comment from [email protected] on 2006-01-26 16:03 EST --
The proposed patch is attachment 123745
Discussion:
ping! if fixed in rawhide please close this bug, otherwise please try to fix
this before FC5Test3 (Feb 13)
---
it's now fixed in 3.01-12
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow (FC5 test2)
bugzilla·2006-01-31·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow (FC5 test2)
CVE-2006-0301 PDF splash handling heap overflow (FC5 test2)
+++ This bug was initially created as a clone of Bug #179054 +++
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
The proposed patch is attachment 123745
-- Additional comment from [email protected] on 2006-01-26 16:28 EST --
There is a repoducer for this issue in attachment 123746
Discussion:
ping! if fixed in rawhide please close this bug, otherwise please try to fix
this before FC5Test3 (Feb 13)
---
This bug doesn't affect the rawhide build of poppler. In rawhide, poppler use
the cairo rendering backend, so the problem doesn't affect that build.
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow
bugzilla·2006-01-26·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow
CVE-2006-0301 PDF splash handling heap overflow
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
The proposed patch is attachment 123745
Discussion:
it's now fixed in kdegraphics-3_5_1-0_2_fc4
---
From User-Agent: XML-RPC
kdegraphics-3.5.1-0.2.fc4 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
Closing bugs in MODIFIED state from prior Fedora releases. If this bug persists
in a current Fedora release (such as Fedora Core 5 or later), please reopen and
set the version appropriately.
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow
bugzilla·2006-01-26·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow
CVE-2006-0301 PDF splash handling heap overflow
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
The proposed patch is attachment 123745
Discussion:
I'm starting to think we don't use splash anywhere in the code.
We definitely build a static convenience library, but we don't appear to link it
to any binary.
Furthermore, running nm on the binaries shows no symbols with the name "Splash"
in them.
gpdf must use its own rendering code.
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow
bugzilla·2006-01-26·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow
CVE-2006-0301 PDF splash handling heap overflow
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
The proposed patch is attachment 123745
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0206.html
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow
bugzilla·2006-01-26·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow
CVE-2006-0301 PDF splash handling heap overflow
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
Discussion:
The proposed patch is attachment 123745
---
From User-Agent: XML-RPC
xpdf-3.01-0.FC4.8 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow
bugzilla·2006-01-26·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow
CVE-2006-0301 PDF splash handling heap overflow
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
The proposed patch is attachment 123745
Discussion:
From User-Agent: XML-RPC
poppler-0.4.5-1.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
Huh, I guess this never got closed...
Bugzilla
CVE-2006-0301 PDF splash handling heap overflow
bugzilla·2006-01-26·CVSS 7.5
CVE-2006-0301 [HIGH] CVE-2006-0301 PDF splash handling heap overflow
CVE-2006-0301 PDF splash handling heap overflow
PDF splash handling heap overflow
Dirk Mueller told vendor-sec about a buffer overflow issue in the xpdf
codebase when handling splash images.
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
Created attachment 123745
Proposed patch
---
The new PDF rasterizer "Splash" is included in xpdf-3.00 and newer, so
this issue is only effected in RHEL4 and FC5/FC5.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txthttp://rhn.redhat.com/errata/RHSA-2006-0206.htmlhttp://secunia.com/advisories/18274http://secunia.com/advisories/18677http://secunia.com/advisories/18707http://secunia.com/advisories/18825http://secunia.com/advisories/18826http://secunia.com/advisories/18834http://secunia.com/advisories/18837http://secunia.com/advisories/18838http://secunia.com/advisories/18839http://secunia.com/advisories/18860http://secunia.com/advisories/18862http://secunia.com/advisories/18864http://secunia.com/advisories/18875http://secunia.com/advisories/18882http://secunia.com/advisories/18908http://secunia.com/advisories/18913http://secunia.com/advisories/18983http://secunia.com/advisories/19377http://securityreason.com/securityalert/470http://securitytracker.com/id?1015576http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747http://www.debian.org/security/2006/dsa-971http://www.debian.org/security/2006/dsa-972http://www.debian.org/security/2006/dsa-974http://www.gentoo.org/security/en/glsa/glsa-200602-04.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200602-05.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200602-12.xmlhttp://www.kde.org/info/security/advisory-20060202-1.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2006:030http://www.mandriva.com/security/advisories?name=MDKSA-2006:031http://www.mandriva.com/security/advisories?name=MDKSA-2006:032http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00039.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0201.htmlhttp://www.securityfocus.com/archive/1/423899/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttp://www.ubuntu.com/usn/usn-249-1http://www.vupen.com/english/advisories/2006/0389http://www.vupen.com/english/advisories/2006/0422https://bugzilla.novell.com/show_bug.cgi?id=141242https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046https://exchange.xforce.ibmcloud.com/vulnerabilities/24391https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10850ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txthttp://rhn.redhat.com/errata/RHSA-2006-0206.htmlhttp://secunia.com/advisories/18274http://secunia.com/advisories/18677http://secunia.com/advisories/18707http://secunia.com/advisories/18825http://secunia.com/advisories/18826http://secunia.com/advisories/18834http://secunia.com/advisories/18837http://secunia.com/advisories/18838http://secunia.com/advisories/18839http://secunia.com/advisories/18860http://secunia.com/advisories/18862http://secunia.com/advisories/18864http://secunia.com/advisories/18875http://secunia.com/advisories/18882http://secunia.com/advisories/18908http://secunia.com/advisories/18913http://secunia.com/advisories/18983http://secunia.com/advisories/19377http://securityreason.com/securityalert/470http://securitytracker.com/id?1015576http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747http://www.debian.org/security/2006/dsa-971http://www.debian.org/security/2006/dsa-972http://www.debian.org/security/2006/dsa-974http://www.gentoo.org/security/en/glsa/glsa-200602-04.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200602-05.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200602-12.xmlhttp://www.kde.org/info/security/advisory-20060202-1.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2006:030http://www.mandriva.com/security/advisories?name=MDKSA-2006:031http://www.mandriva.com/security/advisories?name=MDKSA-2006:032http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00039.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0201.htmlhttp://www.securityfocus.com/archive/1/423899/100/0/threadedhttp://www.securityfocus.com/archive/1/427990/100/0/threadedhttp://www.ubuntu.com/usn/usn-249-1http://www.vupen.com/english/advisories/2006/0389http://www.vupen.com/english/advisories/2006/0422https://bugzilla.novell.com/show_bug.cgi?id=141242https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046https://exchange.xforce.ibmcloud.com/vulnerabilities/24391https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10850
2006-01-30
Published