CVE-2005-3628

critical

Description

Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10287

http://www.securityfocus.com/archive/1/427990/100/0/threaded

http://www.securityfocus.com/archive/1/427053/100/0/threaded

http://www.redhat.com/support/errata/RHSA-2006-0160.html

http://www.mandriva.com/security/advisories?name=MDKSA-2006:012

http://www.mandriva.com/security/advisories?name=MDKSA-2006:011

http://www.mandriva.com/security/advisories?name=MDKSA-2006:010

http://www.debian.org/security/2006/dsa-962

http://www.debian.org/security/2006/dsa-961

http://www.debian.org/security/2006/dsa-950

http://www.debian.org/security/2006/dsa-936

http://www.debian.org/security/2005/dsa-940

http://www.debian.org/security/2005/dsa-938

http://www.debian.org/security/2005/dsa-937

http://www.debian.org/security/2005/dsa-932

http://www.debian.org/security/2005/dsa-931

http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747

http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683

http://secunia.com/advisories/19230

http://secunia.com/advisories/18913

http://secunia.com/advisories/18908

http://secunia.com/advisories/18679

http://secunia.com/advisories/18675

http://secunia.com/advisories/18674

http://secunia.com/advisories/18582

http://secunia.com/advisories/18534

http://secunia.com/advisories/18436

http://secunia.com/advisories/18428

http://secunia.com/advisories/18416

http://secunia.com/advisories/18407

http://secunia.com/advisories/18398

http://secunia.com/advisories/18389

http://secunia.com/advisories/18387

http://secunia.com/advisories/18385

http://secunia.com/advisories/18380

http://secunia.com/advisories/18147

http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html

Details

Source: Mitre, NVD

Published: 2005-12-31

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical