Skip to navigation

CVE Database

CVE-2005-3624

Impact: Important
Public: 2006-01-03

Details

The MITRE CVE dictionary describes this issue as:

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.

Find out more about CVE-2005-3624 from the MITRE CVE dictionary and NIST NVD.

Statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Red Hat security errata

Platform Errata Release Date
Red Hat Enterprise Linux version 2.1 (tetex) RHSA-2006:0160 January 19, 2006
Red Hat Enterprise Linux version 2.1 (xpdf) RHSA-2005:840 December 06, 2005
Red Hat Enterprise Linux version 3 (cups) RHSA-2006:0163 January 11, 2006
Red Hat Enterprise Linux version 3 (tetex) RHSA-2006:0160 January 19, 2006
Red Hat Enterprise Linux version 3 (xpdf) RHSA-2005:840 December 06, 2005
Red Hat Enterprise Linux version 4 (cups) RHSA-2006:0163 January 11, 2006
Red Hat Enterprise Linux version 4 (gpdf) RHSA-2006:0177 January 11, 2006
Red Hat Enterprise Linux version 4 (kdegraphics) RHSA-2005:868 December 20, 2005
Red Hat Enterprise Linux version 4 (tetex) RHSA-2006:0160 January 19, 2006
Red Hat Enterprise Linux version 4 (xpdf) RHSA-2005:840 December 06, 2005

External References

Acknowledgements

Red Hat would like to thank Chris Evans for reporting this issue.

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.