Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libextractorUpgrade xpdfUpgrade cups | Jul 30, 2024 | Dec 31, 2005 |
| Gentoo Linux | — | Upgrade app-office/koffice.Upgrade kde-base/kpdf.Upgrade kde-base/kdegraphics.Upgrade app-office/kword. | Oct 30, 2017 | Dec 31, 2005 |
| Suse | — | Upgrade cups-develUpgrade libcupsimage2Upgrade libcups2Upgrade cups-configUpgrade cupsUpgrade cups-clientUpgrade cups-ddk | Sep 1, 2026 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub