Revision Date: | 2013-04-29 | Version: | 11 | Title: | Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo. | Description: | Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo. | Family: | unix | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2005-3627
| Platform(s): | CentOS Linux 3 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4
| Product(s): | | Definition Synopsis | OS Section: RHEL3, CentOS3 RHEL3 or CentOS3
The operating system installed on the system is Red Hat Enterprise Linux 3
OR CentOS Linux 3.x
AND Configuration section
tetex-latex is earlier than 0:1.0.7-67.9
OR tetex-dvips is earlier than 0:1.0.7-67.9
OR tetex-fonts is earlier than 0:1.0.7-67.9
OR cups-libs is earlier than 1:1.1.17-13.3.36
OR tetex is earlier than 0:1.0.7-67.9
OR cups-devel is earlier than 1:1.1.17-13.3.36
OR tetex-afm is earlier than 0:1.0.7-67.9
OR xpdf is earlier than 1:2.02-9.8
OR tetex-xdvi is earlier than 0:1.0.7-67.9
OR cups is earlier than 1:1.1.17-13.3.36
OR OS Section: RHEL4, CentOS4, Oracle Linux 4
RHEL4, CentOS4 or Oracle Linux 4
The operating system installed on the system is Red Hat Enterprise Linux 4
OR CentOS Linux 4.x
OR Oracle Linux 4.x
AND Configuration section
tetex-latex is earlier than 0:2.0.2-22.EL4.7
OR kdegraphics-devel is earlier than 7:3.3.1-3.6
OR tetex-dvips is earlier than 0:2.0.2-22.EL4.7
OR kdegraphics is earlier than 7:3.3.1-3.6
OR tetex-fonts is earlier than 0:2.0.2-22.EL4.7
OR cups-libs is earlier than 1:1.1.22-0.rc1.9.10
OR tetex is earlier than 0:2.0.2-22.EL4.7
OR gpdf is earlier than 0:2.8.2-7.4
OR cups-devel is earlier than 1:1.1.22-0.rc1.9.10
OR tetex-afm is earlier than 0:2.0.2-22.EL4.7
OR xpdf is earlier than 1:3.00-11.10
OR tetex-xdvi is earlier than 0:2.0.2-22.EL4.7
OR tetex-doc is earlier than 0:2.0.2-22.EL4.7
OR cups is earlier than 1:1.1.22-0.rc1.9.10
|
|