CVE-2006-0301
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.51% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- xpdf/xpdf
- Source
- secalert@redhat.com
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txtPatch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0206.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/18274Vendor Advisory
- http://secunia.com/advisories/18677Patch, Vendor Advisory
- http://secunia.com/advisories/18707Patch, Vendor Advisory
- http://secunia.com/advisories/18825Patch, Vendor Advisory
- http://secunia.com/advisories/18826Patch, Vendor Advisory
- http://secunia.com/advisories/18834Patch, Vendor Advisory
- http://secunia.com/advisories/18837Patch, Vendor Advisory
- http://secunia.com/advisories/18838Patch, Vendor Advisory
- http://secunia.com/advisories/18839Patch, Vendor Advisory
- http://secunia.com/advisories/18860Patch, Vendor Advisory
- http://secunia.com/advisories/18862Patch, Vendor Advisory
- http://secunia.com/advisories/18864Patch, Vendor Advisory
- http://secunia.com/advisories/18875Vendor Advisory
- http://secunia.com/advisories/18882Patch, Vendor Advisory
- http://secunia.com/advisories/18908Patch, Vendor Advisory
- http://secunia.com/advisories/18913Patch, Vendor Advisory
- http://secunia.com/advisories/18983Patch, Vendor Advisory
- http://secunia.com/advisories/19377Patch, Vendor Advisory
- http://securityreason.com/securityalert/470
- http://securitytracker.com/id?1015576Patch
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683Patch
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747Patch
- http://www.debian.org/security/2006/dsa-971Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-972Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-974Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200602-04.xmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200602-05.xmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200602-12.xmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.