CVE-2005-3625 PUBLISHED CVSS 10 CRITICAL

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."

EPSS 11.29% · 93.5th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
11.29%
93.5th percentile

Affected Products

VendorProductVersions
turbolinuxturbolinux_home
kdekoffice1.4.2, 1.4, 1.4.1
redhatlinux9.0, 7.3
redhatlinux_advanced_workstation2.1, 2.1
turbolinuxturbolinux_workstation8.0
turbolinuxturbolinux_personal
easy_software_productscups1.1.23, *, 1.1.23_rc1
sgipropack3.0
kdekword1.4.2
turbolinuxturbolinux10, *
redhatenterprise_linux4.0, 3.0, 3.0
kdekpdf3.2, 3.4.3
gentoolinux
scoopenserver6.0, 5.0.7
turbolinuxturbolinux_desktop10.0
trustixsecure_linux2.2, 2.0, 3.0
ubuntuubuntu_linux5.04, 5.04, 5.10
turbolinuxturbolinux_multimedia
mandrakesoftmandrake_linux2006, 10.1, 2006
redhatenterprise_linux_desktop4.0, 3.0

…and 14 more

Timeline

References

…and 68 more

Open in Interactive Console →