CVE Vulnerabilities

CVE-2005-3625

Published: Dec 31, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka Infinite CPU spins.

Affected Software

Name Vendor Start Version End Version
Cups Easy_software_products 1.1.22 1.1.22
Cups Easy_software_products 1.1.22_rc1 1.1.22_rc1
Cups Easy_software_products 1.1.23 1.1.23
Cups Easy_software_products 1.1.23_rc1 1.1.23_rc1
Kdegraphics Kde 3.2 3.2
Kdegraphics Kde 3.4.3 3.4.3
Koffice Kde 1.4 1.4
Koffice Kde 1.4.1 1.4.1
Koffice Kde 1.4.2 1.4.2
Kpdf Kde 3.2 3.2
Kpdf Kde 3.4.3 3.4.3
Kword Kde 1.4.2 1.4.2
Libextractor Libextractor * *
Poppler Poppler 0.4.2 0.4.2
Propack Sgi 3.0 3.0
Tetex Tetex 1.0.7 1.0.7
Tetex Tetex 2.0 2.0
Tetex Tetex 2.0.1 2.0.1
Tetex Tetex 2.0.2 2.0.2
Tetex Tetex 3.0 3.0
Xpdf Xpdf 3.0 3.0
Linux Conectiva 10.0 10.0
Red Hat Enterprise Linux 3 RedHat xpdf-1:2.02-9.8 *
Red Hat Enterprise Linux 3 RedHat tetex-0:1.0.7-67.9 *
Red Hat Enterprise Linux 3 RedHat cups-1:1.1.17-13.3.36 *
Red Hat Enterprise Linux 4 RedHat xpdf-1:3.00-11.10 *
Red Hat Enterprise Linux 4 RedHat kdegraphics-7:3.3.1-3.6 *
Red Hat Enterprise Linux 4 RedHat tetex-0:2.0.2-22.EL4.7 *
Red Hat Enterprise Linux 4 RedHat cups-1:1.1.22-0.rc1.9.10 *
Red Hat Enterprise Linux 4 RedHat gpdf-0:2.8.2-7.4 *
Gpdf Ubuntu dapper *
Gpdf Ubuntu edgy *
Kdegraphics Ubuntu dapper *
Kdegraphics Ubuntu devel *
Kdegraphics Ubuntu edgy *
Kdegraphics Ubuntu feisty *
Koffice Ubuntu dapper *
Koffice Ubuntu devel *
Koffice Ubuntu edgy *
Koffice Ubuntu feisty *
Poppler Ubuntu dapper *
Poppler Ubuntu devel *
Poppler Ubuntu edgy *
Poppler Ubuntu feisty *

References