VDB
CVE-2005-0064
CVE-2005-0064
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
EPSS 7.22% · 94.1th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
7.22%
94.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xpdf | xpdf | *, 0.2, 0.3 |
| n/a | n/a | n/a |
Timeline
- Jan 19, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- MDKSA-2005:016 vendor-advisory
- 2005-0003 vendor-advisory
- 20050118 Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow third-party-advisory
- SCOSA-2005.42 vendor-advisory
- DSA-648 vendor-advisory
- ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch url
- DSA-645 vendor-advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000921 patch
- http://secunia.com/advisories/17277 technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:019 technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:021 technical
- http://www.redhat.com/support/errata/RHSA-2005-053.html patch
- http://marc.info/?l=bugtraq&m=110625368019554&w=2 technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:017 technical
- http://www.redhat.com/support/errata/RHSA-2005-026.html technical
- http://www.redhat.com/support/errata/RHSA-2005-034.html patch
- http://www.redhat.com/support/errata/RHSA-2005-059.html patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11781 technical
- https://security.gentoo.org/glsa/200501-28 technical
- https://security.gentoo.org/glsa/200502-10 technical
…and 8 more