VDB

CVE-2005-3627

CVE-2005-3627 PUBLISHED CVSS 7.5 HIGH

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.

EPSS 5.52% · 92.3th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
5.52%
92.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
xpdfxpdf

Timeline

  • Dec 31, 2005 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Feb 10, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • Apr 12, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Sep 9, 2023 EPSS Score

References

…and 69 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›