PT-2005-1038 · Foxtail Technology+3 · Xpdf+3
Chris Evans
·
Publicado
2005-12-06
·
Atualizado
2018-10-19
·
CVE-2005-3625
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
kdegraphics versions prior to 3.4.3-r3
pdftohtml (affected versions not specified)
Xpdf (affected versions not specified)
Description
The issue affects multiple components, including kdegraphics and pdftohtml, allowing remote exploitation that may lead to confidentiality, integrity, and availability breaches. Specifically, Xpdf is vulnerable to a denial of service (infinite loop) via prematurely ended streams, such as CCITTFaxDecode and DCTDecode streams.
Recommendations
For kdegraphics versions prior to 3.4.3-r3, update to version 3.4.3-r3 or later.
For pdftohtml, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Xpdf, consider disabling the use of CCITTFaxDecode and DCTDecode streams until a patch is available.
Exploit
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Xpdf
Kdegraphics
Pdftohtml