7.6
CVSSv2

CVE-2006-1244

Published: 15/03/2006 Updated: 03/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.

Vulnerable Product Search on Vulmon Subscribe to Product

libextractor libextractor 0.3.8

libextractor libextractor 0.3.9

xpdf xpdf 0.92

xpdf xpdf 0.93

xpdf xpdf 1.0

xpdf xpdf 3.0

xpdf xpdf 3.0.1

libextractor libextractor 0.3.6

libextractor libextractor 0.3.7

xpdf xpdf 0.90

xpdf xpdf 0.91

xpdf xpdf 2.2

xpdf xpdf 2.3

libextractor libextractor 0.4

libextractor libextractor 0.4.1

xpdf xpdf 1.0a

xpdf xpdf 1.1

xpdf xpdf 3.0.1_pl1

xpdf xpdf 3.0_pl2

gnome gpdf 2.8.2

libextractor libextractor 0.3.11

libextractor libextractor 0.4.2

libextractor libextractor 0.5

xpdf xpdf 2.0

xpdf xpdf 2.1

xpdf xpdf 3.0_pl3

debian debian linux 3.1

Vendor Advisories

Derek Noonburg discovered several integer overflows in the XPDF code, which is present in xpdf, the Poppler library, and tetex-bin By tricking an user into opening a specially crafted PDF file, an attacker could exploit this to execute arbitrary code with the privileges of the application that processes the document ...
Derek Noonburg has fixed several potential vulnerabilities in xpdf, which are also present in gpdf, the Portable Document Format (PDF) viewer with Gtk bindings The old stable distribution (woody) does not contain gpdf packages For the stable distribution (sarge) these problems have been fixed in version 282-12sarge4 For the unstable distribut ...
Derek Noonburg has fixed several potential vulnerabilities in xpdf, the Portable Document Format (PDF) suite, which is also present in koffice, the KDE Office Suite The old stable distribution (woody) does not contain koffice packages For the stable distribution (sarge) these problems have been fixed in version 135-4sarge3 For the unstable d ...
Derek Noonburg has fixed several potential vulnerabilities in xpdf, the Portable Document Format (PDF) suite, which are also present in pdfkitframework, the GNUstep framework for rendering PDF content The old stable distribution (woody) does not contain pdfkitframework packages For the stable distribution (sarge) these problems have been fixed ...
Derek Noonburg has fixed several potential vulnerabilities in xpdf, the Portable Document Format (PDF) suite The old stable distribution (woody) does not seem to be affected For the stable distribution (sarge) these problems have been fixed in version 300-136 For the unstable distribution (sid) these problems have been fixed in version 301-7 ...
Derek Noonburg has fixed several potential vulnerabilities in xpdf, which are also present in pdftohtml, a utility that translates PDF documents into HTML format The old stable distribution (woody) does not contain pdftohtml packages For the stable distribution (sarge) these problems have been fixed in version 036-11sarge2 For the unstable dist ...