Upstream information
Description
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
National Vulnerability Database | |
---|---|
Base Score | 9.3 |
Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Complete |
Integrity Impact | Complete |
Availability Impact | Complete |
SUSE Security Advisories:
- SUSE-SR:2005:001, published Wednesday, Jan 12th 2004 18:00 MEST
- SUSE-SR:2005:002, published Wednesday, Jan 26th 2005 17:00 MEST
- SUSE-SR:2005:003, published Wednesday, Feb 4th 2005 15:00 MEST
- SUSE-SR:2005:008, published Fri, 18 Mar 2005 15:00:00 +0000
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 01:04:36 2013CVE page last modified: Fri Dec 8 16:10:43 2023