CVE-2006-1244
published 2006-03-15CVE-2006-1244: Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d)…
PriorityP425high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
2.14%
80.3th percentile
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xpdf | — | — |
| gnome | gpdf | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| libextractor | libextractor | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xpdf vulnerabilities
vendor_ubuntu·2006-04-13
CVE-2006-1244 xpdf vulnerabilities
Title: xpdf vulnerabilities
Summary: xpdf vulnerabilities
Derek Noonburg discovered several integer overflows in the XPDF code,
which is present in xpdf, the Poppler library, and tetex-bin. By
tricking an user into opening a specially crafted PDF file, an
attacker could exploit this to execute arbitrary code with the
privileges of the application that processes the document.
The CUPS printing system also uses XPDF code to convert PDF files to
PostScript. By attempting to print such a crafted PDF file, a remote
attacker could execute arbitrary code with the privileges of the
printer server (user 'cupsys').
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2006-1244: xpdf - Unspecified vulnerability in certain versions of xpdf after 3.00, as used in var...
vendor_debian·2006·CVSS 5.0
CVE-2006-1244 [MEDIUM] CVE-2006-1244: xpdf - Unspecified vulnerability in certain versions of xpdf after 3.00, as used in var...
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-2hp4-p7vf-34wc: Unspecified vulnerability in certain versions of xpdf after 3
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-1244 [MEDIUM] GHSA-2hp4-p7vf-34wc: Unspecified vulnerability in certain versions of xpdf after 3
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/18948http://secunia.com/advisories/19021http://secunia.com/advisories/19065http://secunia.com/advisories/19091http://secunia.com/advisories/19164http://secunia.com/advisories/19364http://secunia.com/advisories/19644http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gzhttp://www.debian.org/security/2006/dsa-1019http://www.debian.org/security/2006/dsa-979http://www.debian.org/security/2006/dsa-982http://www.debian.org/security/2006/dsa-983http://www.debian.org/security/2006/dsa-984http://www.debian.org/security/2006/dsa-998http://www.osvdb.org/23834http://www.securityfocus.com/bid/16748https://usn.ubuntu.com/270-1/http://secunia.com/advisories/18948http://secunia.com/advisories/19021http://secunia.com/advisories/19065http://secunia.com/advisories/19091http://secunia.com/advisories/19164http://secunia.com/advisories/19364http://secunia.com/advisories/19644http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gzhttp://www.debian.org/security/2006/dsa-1019http://www.debian.org/security/2006/dsa-979http://www.debian.org/security/2006/dsa-982http://www.debian.org/security/2006/dsa-983http://www.debian.org/security/2006/dsa-984http://www.debian.org/security/2006/dsa-998http://www.osvdb.org/23834http://www.securityfocus.com/bid/16748https://usn.ubuntu.com/270-1/
2006-03-15
Published