CVE-2005-3626 (NVD)

2005-12-31

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.

Products Linux, Debian_linux, Cups, Linux, Kdegraphics, Koffice, Kpdf, Kword, Libextractor, Mandrake_linux, Mandrake_linux_corporate_server, Poppler, Enterprise_linux, Enterprise_linux_desktop, Fedora_core, Linux, Linux_advanced_workstation, Openserver, Propack, Slackware_linux, Suse_linux, Tetex, Secure_linux, Turbolinux, Turbolinux_appliance_server, Turbolinux_desktop, Turbolinux_home, Turbolinux_multimedia, Turbolinux_personal, Turbolinux_server, Turbolinux_workstation, Ubuntu_linux, Xpdf
Type Resource Management Errors (CWE-399)
First patch - None (likely due to unavailable code)
Links http://www.debian.org/security/2005/dsa-938
• ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U
http://www.debian.org/security/2005/dsa-940
http://secunia.com/advisories/25729
http://www.kde.org/info/security/advisory-20051207-2.txt