The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xpdfUpgrade popplerUpgrade libextractorUpgrade cups | Jul 30, 2024 | Dec 31, 2005 |
| Gentoo Linux | — | Upgrade app-text/gpdf.Upgrade kde-base/kpdf.Upgrade app-office/koffice.Upgrade kde-base/kdegraphics.Upgrade app-office/kword.Upgrade app-text/xpdf.Upgrade media-libs/libextractor.Upgrade app-text/pdftohtml.Upgrade app-text/poppler. | Oct 30, 2017 | Dec 31, 2005 |
| Suse | — | Upgrade cups-clientUpgrade cups-ddkUpgrade cupsUpgrade libcupsimage2Upgrade cups-configUpgrade libcups2Upgrade cups-devel | Sep 1, 2026 | Jun 28, 2013 |
| Ubuntu | — | Upgrade xpdf-utilsUpgrade cupsysUpgrade kword | Nov 8, 2024 | Dec 31, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub