Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2005-3191

Опубликовано: 07 дек. 2005
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1

Описание

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.

РелизСтатусПримечание
dapper

not-affected

devel

released

1.3.2-1ubuntu1
edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.10.0-2
devel

DNE

edgy

released

2.10.0-2
feisty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

3.5.2-0ubuntu6
devel

released

3.5.2-0ubuntu6
edgy

released

3.5.2-0ubuntu6
feisty

released

3.5.2-0ubuntu6
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

1.5.0-0ubuntu9.2
devel

released

1.6.3-0ubuntu5
edgy

released

1.5.2-0ubuntu2.2
feisty

released

1.6.2-0ubuntu1.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.5.14-1
devel

released

0.5.14-1
edgy

released

0.5.14-1
feisty

released

0.5.14-1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.36-13
devel

DNE

edgy

released

0.36-13
feisty

released

0.36-13
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.5.1-0ubuntu7.2
devel

released

0.6-0ubuntu1
edgy

released

0.5.4-0ubuntu4.2
feisty

released

0.5.4-0ubuntu8.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

3.0-13ubuntu6
devel

DNE

edgy

released

3.0-13ubuntu6
feisty

released

3.0-13ubuntu6
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

3.01-7ubuntu0.1
devel

released

3.01-9ubuntu3
edgy

released

3.01-9ubuntu1.1
feisty

released

3.01-9ubuntu3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 86%
0.03031
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

redhat
больше 19 лет назад

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.

nvd
больше 19 лет назад

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.

debian
больше 19 лет назад

Multiple heap-based buffer overflows in the (1) DCTStream::readProgres ...

github
больше 3 лет назад

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.

fstec
больше 19 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 86%
0.03031
Низкий

5.1 Medium

CVSS2

Уязвимость CVE-2005-3191