Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.
CVSS Details
- CVSS 3.1 Base Score: 5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libextractorUpgrade popplerUpgrade xpdfUpgrade cups | Jul 30, 2024 | Dec 7, 2005 |
| Gentoo Linux | — | Upgrade app-text/xpdf.Upgrade app-text/poppler.Upgrade kde-base/kdegraphics.Upgrade app-office/koffice.Upgrade app-office/kword.Upgrade net-print/cups.Upgrade kde-base/kpdf.Upgrade app-text/gpdf. | Oct 30, 2017 | Dec 6, 2005 |
| Suse | — | Upgrade cups | Feb 17, 2015 | Dec 6, 2005 |
| Ubuntu | — | Upgrade tetex-binUpgrade cupsys-bsdUpgrade cupsys-clientUpgrade cupsys | Nov 8, 2024 | Dec 7, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub