Skip to navigation

CVE Database

CVE-2005-3627

Impact: Important
Public: 2006-01-03

Details

The MITRE CVE dictionary describes this issue as:

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.

Find out more about CVE-2005-3627 from the MITRE CVE dictionary and NIST NVD.

Statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Red Hat security errata

Platform Errata Release Date
Red Hat Enterprise Linux version 2.1 (tetex) RHSA-2006:0160 January 19, 2006
Red Hat Enterprise Linux version 2.1 (xpdf) RHSA-2005:840 December 06, 2005
Red Hat Enterprise Linux version 3 (cups) RHSA-2006:0163 January 11, 2006
Red Hat Enterprise Linux version 3 (tetex) RHSA-2006:0160 January 19, 2006
Red Hat Enterprise Linux version 3 (xpdf) RHSA-2005:840 December 06, 2005
Red Hat Enterprise Linux version 4 (cups) RHSA-2006:0163 January 11, 2006
Red Hat Enterprise Linux version 4 (gpdf) RHSA-2006:0177 January 11, 2006
Red Hat Enterprise Linux version 4 (kdegraphics) RHSA-2005:868 December 20, 2005
Red Hat Enterprise Linux version 4 (tetex) RHSA-2006:0160 January 19, 2006
Red Hat Enterprise Linux version 4 (xpdf) RHSA-2005:840 December 06, 2005

External References

Acknowledgements

Red Hat would like to thank Chris Evans for reporting this issue.

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.