PT-2006-1010 · Debian+3 · Pdfkit.Framework+5

Dirk Mueller

+1

·

Published

2006-01-30

·

Updated

2024-06-15

·

CVE-2006-0301

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: pdfkit.framework versions prior to the fixed version kdegraphics versions prior to 3.4.3-r4
Description: The issue involves multiple vulnerabilities in the pdfkit.framework package of Debian GNU/Linux and kdegraphics package of Gentoo Linux. These vulnerabilities can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Specifically, a heap-based buffer overflow in Splash.cc, as used in xpdf and other products including pdfkit.framework and kdegraphics, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images.
Recommendations: For pdfkit.framework, update to a version that contains a fix for this issue. For kdegraphics versions prior to 3.4.3-r4, update to version 3.4.3-r4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable pdfkit.framework and kdegraphics packages until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02546
BDU:2015-09498
CVE-2006-0301
DSA-1019-1
DSA-971-1
DSA-972-1
DSA-974-1
DSA-979-1
DSA-982-1
DSA-983-1
DSA-984-1
DSA-998-1
OPENSUSE-SU-2024:11181-1
RHSA-2006:0201
RHSA-2006:0206
RHSA-2006_0201
RHSA-2006_0206

Affected Products

Debian
Gentoo Linux
Red Hat
Kdegraphics
Pdfkit.Framework
Xpdf