PT-2004-1010 · Tetex+4 · Tetex-Bin+4

Matthias Geerdsen

·

Published

2004-12-22

·

Updated

2018-10-03

·

CVE-2004-1125

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions xpdf versions 3.00 tetex-bin versions prior to the fixed version kpdf versions 3.2.x through 3.2.3 kpdf versions 3.3.x through 3.3.2 cupsys-pstoraster (affected versions not specified)
Description The issue is related to a buffer overflow in the Gfx::doImage function, which can be triggered by a crafted PDF file, potentially allowing remote attackers to cause a denial of service or execute arbitrary code. Additionally, multiple vulnerabilities in the cupsys-pstoraster package may lead to breaches of confidentiality, integrity, and availability of protected information, with possible remote exploitation.
Recommendations For xpdf version 3.00, update to a version that fixes the buffer overflow issue in the Gfx::doImage function. For tetex-bin, update to a version that fixes the vulnerabilities. For kpdf versions 3.2.x through 3.2.3 and 3.3.x through 3.3.2, update to a version that fixes the vulnerabilities. For cupsys-pstoraster, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02034
CVE-2004-1125
DSA-619-1
DSA-621-1
RHSA-2005:013
RHSA-2005:018
RHSA-2005:026
RHSA-2005:034
RHSA-2005:053
RHSA-2005:057
RHSA-2005:066
RHSA-2005:354
RHSA-2005_013
RHSA-2005_018
RHSA-2005_026
RHSA-2005_034
RHSA-2005_053
RHSA-2005_057
RHSA-2005_066
RHSA-2005_354

Affected Products

Red Hat
Cupsys-Pstoraster
Kpdf
Tetex-Bin
Xpdf