Description
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-931-1 | New xpdf packages fix arbitrary code execution |
Debian DSA |
DSA-932-1 | New kpdf packages fix arbitrary code execution |
Debian DSA |
DSA-936-1 | New libextractor packages fix arbitrary code execution |
Debian DSA |
DSA-937-1 | New tetex-bin packages fix arbitrary code execution |
Debian DSA |
DSA-938-1 | New koffice packages fix arbitrary code execution |
Debian DSA |
DSA-940-1 | New gpdf packages fix arbitrary code execution |
Debian DSA |
DSA-950-1 | New CUPS packages fix arbitrary code execution |
Debian DSA |
DSA-961-1 | New pdfkit.framework packages fix arbitrary code execution |
Debian DSA |
DSA-962-1 | New pdftohtml packages fix arbitrary code execution |
Ubuntu USN |
USN-236-1 | xpdf vulnerabilities |
Ubuntu USN |
USN-236-2 | xpdf vulnerabilities in kword, kpdf |
References
History
No history.
Subscriptions
Conectiva
Subscribe
Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Easy Software Products
Subscribe
Cups
Subscribe
Gentoo
Subscribe
Linux
Subscribe
Kde
Subscribe
Kdegraphics
Subscribe
Koffice
Subscribe
Kpdf
Subscribe
Kword
Subscribe
Libextractor
Subscribe
Libextractor
Subscribe
Mandrakesoft
Subscribe
Mandrake Linux
Subscribe
Mandrake Linux Corporate Server
Subscribe
Poppler
Subscribe
Poppler
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Fedora Core
Subscribe
Linux
Subscribe
Linux Advanced Workstation
Subscribe
Sco
Subscribe
Openserver
Subscribe
Sgi
Subscribe
Propack
Subscribe
Slackware
Subscribe
Slackware Linux
Subscribe
Suse
Subscribe
Suse Linux
Subscribe
Tetex
Subscribe
Tetex
Subscribe
Trustix
Subscribe
Secure Linux
Subscribe
Turbolinux
Subscribe
Turbolinux
Subscribe
Turbolinux Appliance Server
Subscribe
Turbolinux Desktop
Subscribe
Turbolinux Home
Subscribe
Turbolinux Multimedia
Subscribe
Turbolinux Personal
Subscribe
Turbolinux Server
Subscribe
Turbolinux Workstation
Subscribe
Ubuntu
Subscribe
Ubuntu Linux
Subscribe
Xpdf
Subscribe
Xpdf
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T23:17:23.366Z
Reserved: 2005-11-16T00:00:00.000Z
Link: CVE-2005-3625
No data.
Status : Deferred
Published: 2005-12-31T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-3625
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN