CVE-2005-3626
Last modified
CVE-2005-3626 is a vulnerability of currently unknown severity. Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.. EPSS estimates a 3.41% chance of exploitation in the next 30 days.
Description
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Easy Software Products | Cups | 1.1.22 | — |
| Easy Software Products | Cups | 1.1.22_rc1 | — |
| Easy Software Products | Cups | 1.1.23 | — |
| Easy Software Products | Cups | 1.1.23_rc1 | — |
| Kde | Kdegraphics | 3.2 | — |
| Kde | Kdegraphics | 3.4.3 | — |
| Kde | Koffice | 1.4 | — |
| Kde | Koffice | 1.4.1 | — |
| Kde | Koffice | 1.4.2 | — |
| Kde | Kpdf | 3.2 | — |
| Kde | Kpdf | 3.4.3 | — |
| Kde | Kword | 1.4.2 | — |
| Libextractor | Libextractor | All versions | — |
| Poppler | Poppler | 0.4.2 | — |
| Sgi | Propack | 3.0 | Sp6 |
| Tetex | Tetex | 1.0.7 | — |
| Tetex | Tetex | 2.0 | — |
| Tetex | Tetex | 2.0.1 | — |
| Tetex | Tetex | 2.0.2 | — |
| Tetex | Tetex | 3.0 | — |
| Xpdf | Xpdf | 3.0 | — |
| Conectiva | Linux | 10.0 | — |
| Debian | Debian Linux | 3.0 | — |
| Debian | Debian Linux | 3.1 | — |
| Gentoo | Linux | All versions | — |
| Mandrakesoft | Mandrake Linux | 10.1 | — |
| Mandrakesoft | Mandrake Linux | 10.2 | — |
| Mandrakesoft | Mandrake Linux | 2006 | — |
| Mandrakesoft | Mandrake Linux Corporate Server | 2.1 | — |
| Mandrakesoft | Mandrake Linux Corporate Server | 3.0 | — |
| Redhat | Enterprise Linux | 2.1 | — |
| Redhat | Enterprise Linux | 3.0 | — |
| Redhat | Enterprise Linux | 4.0 | — |
| Redhat | Enterprise Linux Desktop | 3.0 | — |
| Redhat | Enterprise Linux Desktop | 4.0 | — |
| Redhat | Fedora Core | core_1.0 | — |
| Redhat | Fedora Core | core_2.0 | — |
| Redhat | Fedora Core | core_3.0 | — |
| Redhat | Fedora Core | core_4.0 | — |
| Redhat | Linux | 7.3 | — |
| Redhat | Linux | 9.0 | — |
| Redhat | Linux Advanced Workstation | 2.1 | — |
| Sco | Openserver | 5.0.7 | — |
| Sco | Openserver | 6.0 | — |
| Slackware | Slackware Linux | 9.0 | — |
| Slackware | Slackware Linux | 9.1 | — |
| Slackware | Slackware Linux | 10.0 | — |
| Slackware | Slackware Linux | 10.1 | — |
| Slackware | Slackware Linux | 10.2 | — |
| Suse | Suse Linux | 1.0 | — |
Showing 50 of 73 affected configurations. See NVD for the full list.
References
- http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlPatch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0177.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/18303Vendor Advisory
- http://secunia.com/advisories/18312Patch, Vendor Advisory
- http://secunia.com/advisories/18313Patch, Vendor Advisory
- http://secunia.com/advisories/18329Vendor Advisory
- http://secunia.com/advisories/18332Vendor Advisory
- http://secunia.com/advisories/18334Patch, Vendor Advisory
- http://secunia.com/advisories/18335Patch, Vendor Advisory
- http://secunia.com/advisories/18338Patch, Vendor Advisory
- http://secunia.com/advisories/18349Patch, Vendor Advisory
- http://secunia.com/advisories/18375Vendor Advisory
- http://secunia.com/advisories/18385Patch, Vendor Advisory
- http://secunia.com/advisories/18387Patch, Vendor Advisory
- http://secunia.com/advisories/18389Patch, Vendor Advisory
- http://secunia.com/advisories/18398Patch, Vendor Advisory
- http://secunia.com/advisories/18407Patch, Vendor Advisory
- http://secunia.com/advisories/18416Patch, Vendor Advisory
- http://secunia.com/advisories/18423Patch, Vendor Advisory
- http://secunia.com/advisories/18448Patch, Vendor Advisory
- http://secunia.com/advisories/18517Patch, Vendor Advisory
- http://secunia.com/advisories/18534Patch, Vendor Advisory
- http://secunia.com/advisories/18554Patch, Vendor Advisory
- http://secunia.com/advisories/18582Patch, Vendor Advisory
- http://secunia.com/advisories/18642Vendor Advisory
- http://secunia.com/advisories/18644Vendor Advisory
- http://secunia.com/advisories/18674Vendor Advisory
- http://secunia.com/advisories/18675Vendor Advisory
- http://secunia.com/advisories/18679Vendor Advisory
- http://www.debian.org/security/2006/dsa-936Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-950Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-961Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200601-02.xmlPatch, Vendor Advisory
- http://www.kde.org/info/security/advisory-20051207-2.txtPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0160.htmlPatch, Vendor Advisory
- http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.htmlPatch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0177.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/18303Vendor Advisory
- http://secunia.com/advisories/18312Patch, Vendor Advisory
- http://secunia.com/advisories/18313Patch, Vendor Advisory
- http://secunia.com/advisories/18329Vendor Advisory
- http://secunia.com/advisories/18332Vendor Advisory
- http://secunia.com/advisories/18334Patch, Vendor Advisory
- http://secunia.com/advisories/18335Patch, Vendor Advisory
- http://secunia.com/advisories/18338Patch, Vendor Advisory
- http://secunia.com/advisories/18349Patch, Vendor Advisory
- http://secunia.com/advisories/18375Vendor Advisory
- http://secunia.com/advisories/18385Patch, Vendor Advisory
- http://secunia.com/advisories/18387Patch, Vendor Advisory
- http://secunia.com/advisories/18389Patch, Vendor Advisory
- http://secunia.com/advisories/18398Patch, Vendor Advisory
- http://secunia.com/advisories/18407Patch, Vendor Advisory
- http://secunia.com/advisories/18416Patch, Vendor Advisory
- http://secunia.com/advisories/18423Patch, Vendor Advisory
- http://secunia.com/advisories/18448Patch, Vendor Advisory
- http://secunia.com/advisories/18517Patch, Vendor Advisory
- http://secunia.com/advisories/18534Patch, Vendor Advisory
- http://secunia.com/advisories/18554Patch, Vendor Advisory
- http://secunia.com/advisories/18582Patch, Vendor Advisory
- http://secunia.com/advisories/18642Vendor Advisory
- http://secunia.com/advisories/18644Vendor Advisory
- http://secunia.com/advisories/18674Vendor Advisory
- http://secunia.com/advisories/18675Vendor Advisory
- http://secunia.com/advisories/18679Vendor Advisory
- http://www.debian.org/security/2006/dsa-936Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-950Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-961Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200601-02.xmlPatch, Vendor Advisory
- http://www.kde.org/info/security/advisory-20051207-2.txtPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0160.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3626?
How severe is CVE-2005-3626?
How do I fix CVE-2005-3626?
Are you affected by CVE-2005-3626?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
