Lucene search

K
cveMitreCVE-2006-6146
HistoryNov 28, 2006 - 11:28 p.m.

CVE-2006-6146

2006-11-2823:28:00
mitre
web.nvd.nist.gov
23
cve-2006-6146
buffer overflow
hpdf_page_circle
libharu
denial of service
application crash
pdf
security vulnerability

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.003

Percentile

65.1%

Buffer overflow in the HPDF_Page_Circle function in hpdf_page_operator.c in Takeshi Kanno Haru Free PDF Library (libharu2, aka libharu) 2.0.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via certain arguments that yield a large amount of PDF data, as demonstrated by a filled circle.

Affected configurations

Nvd
Node
takeshi_kannoharu_free_pdf_libraryMatch2.0
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.1
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.2
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.3
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.4
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.5
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.6
OR
takeshi_kannoharu_free_pdf_libraryMatch2.0.7
VendorProductVersionCPE
takeshi_kannoharu_free_pdf_library2.0cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.1cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.1:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.2cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.2:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.3cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.3:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.4cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.4:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.5cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.5:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.6cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.6:*:*:*:*:*:*:*
takeshi_kannoharu_free_pdf_library2.0.7cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.7:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

AI Score

7.1

Confidence

High

EPSS

0.003

Percentile

65.1%

Related for CVE-2006-6146