CVE-2005-3625

Description

From CVE.org

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."

Statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Acknowledgements

Red Hat would like to thank Chris Evans for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.