PT-2005-1038 · Foxtail Technology+3 · Xpdf+3
Chris Evans
·
Published
2005-12-06
·
Updated
2018-10-19
·
CVE-2005-3625
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
kdegraphics versions prior to 3.4.3-r3
pdftohtml (affected versions not specified)
Xpdf (affected versions not specified)
Description
The issue affects multiple components, including kdegraphics and pdftohtml, allowing remote exploitation that may lead to confidentiality, integrity, and availability breaches. Specifically, Xpdf is vulnerable to a denial of service (infinite loop) via prematurely ended streams, such as CCITTFaxDecode and DCTDecode streams.
Recommendations
For kdegraphics versions prior to 3.4.3-r3, update to version 3.4.3-r3 or later.
For pdftohtml, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Xpdf, consider disabling the use of CCITTFaxDecode and DCTDecode streams until a patch is available.
Exploit
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Xpdf
Kdegraphics
Pdftohtml