Back to search
CVE-2004-1125
Published: Dec 22, 2004
Modified: Aug 8, 2024
PUBLISHED
Description
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2005:013
vendor-advisory
x_refsource_REDHAT
17277
third-party-advisory
x_refsource_SECUNIA
RHSA-2005:066
vendor-advisory
x_refsource_REDHAT
RHSA-2005:034
vendor-advisory
x_refsource_REDHAT
RHSA-2005:018
vendor-advisory
x_refsource_REDHAT
FLSA:2352
vendor-advisory
x_refsource_FEDORA
FLSA:2353
vendor-advisory
x_refsource_FEDORA
1012646
vdb-entry
x_refsource_SECTRACK
12070
vdb-entry
x_refsource_BID
http://www.kde.org/info/security/advisory-20041223-1.txt
x_refsource_CONFIRM
xpdf-gfx-doimage-bo(18641)
vdb-entry
x_refsource_XF
GLSA-200501-17
vendor-advisory
x_refsource_GENTOO
RHSA-2005:026
vendor-advisory
x_refsource_REDHAT
RHSA-2005:053
vendor-advisory
x_refsource_REDHAT
USN-50-1
vendor-advisory
x_refsource_UBUNTU
GLSA-200501-13
vendor-advisory
x_refsource_GENTOO
20041228 KDE Security Advisory: kpdf Buffer Overflow Vulnerability
mailing-list
x_refsource_BUGTRAQ
GLSA-200412-25
vendor-advisory
x_refsource_GENTOO
20041223 [USN-48-1] xpdf, tetex-bin vulnerabilities
mailing-list
x_refsource_FULLDISC
SUSE-SR:2005:001
vendor-advisory
x_refsource_SUSE
RHSA-2005:354
vendor-advisory
x_refsource_REDHAT
20041221 Multiple Vendor xpdf PDF Viewer Buffer Overflow Vulnerability
third-party-advisory
x_refsource_IDEFENSE
oval:org.mitre.oval:def:10830
vdb-entry
signature
x_refsource_OVAL
CLA-2005:921
vendor-advisory
x_refsource_CONECTIVA
RHSA-2005:057
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now