CVE-2005-0064

UnknownEPSS 7.22%

Last modified

CVE-2005-0064 is a vulnerability of currently unknown severity. Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.. EPSS estimates a 7.22% chance of exploitation in the next 30 days.

Description

Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.

Metrics

EPSS Probability
7.22%

93.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
XpdfXpdf0.2
XpdfXpdf0.3
XpdfXpdf0.4
XpdfXpdf0.5
XpdfXpdf0.5a
XpdfXpdf0.6
XpdfXpdf0.7
XpdfXpdf0.7a
XpdfXpdf0.80
XpdfXpdf0.90
XpdfXpdf0.91
XpdfXpdf0.91a
XpdfXpdf0.91b
XpdfXpdf0.91c
XpdfXpdf0.92
XpdfXpdf0.92a
XpdfXpdf0.92b
XpdfXpdf0.92c
XpdfXpdf0.92d
XpdfXpdf0.92e
XpdfXpdf0.93
XpdfXpdf0.93a
XpdfXpdf0.93b
XpdfXpdf0.93c
XpdfXpdf1.0
XpdfXpdf1.0a
XpdfXpdf1.1
XpdfXpdf2.0
XpdfXpdf2.1
XpdfXpdf2.2
XpdfXpdf2.3
XpdfXpdf3.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-0064?
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
How severe is CVE-2005-0064?
Severity scoring for CVE-2005-0064 is pending analysis. The EPSS model estimates a 7.22% probability of exploitation in the next 30 days.
How do I fix CVE-2005-0064?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-0064?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST