CVE-2005-3192
Last modified
CVE-2005-3192 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.. EPSS estimates a 6.14% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xpdf | Xpdf | 3.0.1 |
References
- http://rhn.redhat.com/errata/RHSA-2005-868.htmlVendor Advisory
- http://secunia.com/advisories/17897/Patch, Vendor Advisory
- http://secunia.com/advisories/17908Vendor Advisory
- http://secunia.com/advisories/17912Vendor Advisory
- http://secunia.com/advisories/17916Vendor Advisory
- http://secunia.com/advisories/17920Vendor Advisory
- http://secunia.com/advisories/17921Vendor Advisory
- http://secunia.com/advisories/17926Vendor Advisory
- http://secunia.com/advisories/17929Vendor Advisory
- http://secunia.com/advisories/17940Vendor Advisory
- http://secunia.com/advisories/17976Vendor Advisory
- http://secunia.com/advisories/18009Vendor Advisory
- http://secunia.com/advisories/18055Vendor Advisory
- http://secunia.com/advisories/18061Vendor Advisory
- http://secunia.com/advisories/18189Vendor Advisory
- http://secunia.com/advisories/18191Vendor Advisory
- http://secunia.com/advisories/18192Vendor Advisory
- http://secunia.com/advisories/18313Vendor Advisory
- http://secunia.com/advisories/18336Vendor Advisory
- http://secunia.com/advisories/18349Vendor Advisory
- http://secunia.com/advisories/18387Vendor Advisory
- http://secunia.com/advisories/18389Vendor Advisory
- http://secunia.com/advisories/18416Vendor Advisory
- http://secunia.com/advisories/18448Vendor Advisory
- http://www.idefense.com/application/poi/display?id=344&type=vulnerabilitiesPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-840.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-867.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-878.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2005-868.htmlVendor Advisory
- http://secunia.com/advisories/17897/Patch, Vendor Advisory
- http://secunia.com/advisories/17908Vendor Advisory
- http://secunia.com/advisories/17912Vendor Advisory
- http://secunia.com/advisories/17916Vendor Advisory
- http://secunia.com/advisories/17920Vendor Advisory
- http://secunia.com/advisories/17921Vendor Advisory
- http://secunia.com/advisories/17926Vendor Advisory
- http://secunia.com/advisories/17929Vendor Advisory
- http://secunia.com/advisories/17940Vendor Advisory
- http://secunia.com/advisories/17976Vendor Advisory
- http://secunia.com/advisories/18009Vendor Advisory
- http://secunia.com/advisories/18055Vendor Advisory
- http://secunia.com/advisories/18061Vendor Advisory
- http://secunia.com/advisories/18189Vendor Advisory
- http://secunia.com/advisories/18191Vendor Advisory
- http://secunia.com/advisories/18192Vendor Advisory
- http://secunia.com/advisories/18313Vendor Advisory
- http://secunia.com/advisories/18336Vendor Advisory
- http://secunia.com/advisories/18349Vendor Advisory
- http://secunia.com/advisories/18387Vendor Advisory
- http://secunia.com/advisories/18389Vendor Advisory
- http://secunia.com/advisories/18416Vendor Advisory
- http://secunia.com/advisories/18448Vendor Advisory
- http://www.idefense.com/application/poi/display?id=344&type=vulnerabilitiesPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-840.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-867.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-878.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3192?
How severe is CVE-2005-3192?
How do I fix CVE-2005-3192?
Are you affected by CVE-2005-3192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
