Lucene search

K
cve[email protected]CVE-2002-1384
HistorySep 01, 2004 - 4:00 a.m.

CVE-2002-1384

2004-09-0104:00:00
web.nvd.nist.gov
23
cve-2002-1384
integer overflow
pdftops
xpdf
cups
arbitrary code execution
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.2%

Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.

Affected configurations

NVD
Node
easy_software_productscupsMatch1.0.4
OR
easy_software_productscupsMatch1.0.4_8
OR
easy_software_productscupsMatch1.1.1
OR
easy_software_productscupsMatch1.1.4
OR
easy_software_productscupsMatch1.1.4_2
OR
easy_software_productscupsMatch1.1.4_3
OR
easy_software_productscupsMatch1.1.4_5
OR
easy_software_productscupsMatch1.1.6
OR
easy_software_productscupsMatch1.1.7
OR
easy_software_productscupsMatch1.1.10
OR
easy_software_productscupsMatch1.1.13
OR
easy_software_productscupsMatch1.1.14
OR
easy_software_productscupsMatch1.1.17
OR
xpdfxpdfMatch0.90
OR
xpdfxpdfMatch0.91
OR
xpdfxpdfMatch1.0
OR
xpdfxpdfMatch1.0a
OR
xpdfxpdfMatch1.1
OR
xpdfxpdfMatch2.0
OR
xpdfxpdfMatch2.1

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.2%