Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libextractorUpgrade cupsUpgrade xpdfUpgrade poppler | Jul 30, 2024 | Dec 31, 2005 |
| Gentoo Linux | — | Upgrade app-text/poppler.Upgrade app-text/xpdf.Upgrade app-office/koffice.Upgrade app-text/gpdf.Upgrade app-text/pdftohtml.Upgrade kde-base/kdegraphics.Upgrade app-office/kword.Upgrade media-libs/libextractor.Upgrade kde-base/kpdf. | Oct 30, 2017 | Dec 31, 2005 |
| Suse | — | Upgrade cups-configUpgrade cups-ddkUpgrade cups-clientUpgrade cups-develUpgrade libcups2Upgrade cupsUpgrade libcupsimage2 | Sep 1, 2026 | Jun 28, 2013 |
| Ubuntu | — | Upgrade kwordUpgrade cupsysUpgrade xpdf-utils | Nov 8, 2024 | Dec 31, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub