Lucene search

K
freebsdFreeBSD24EEE285-09C7-11DA-BC08-0001020EED82
HistoryAug 09, 2005 - 12:00 a.m.

xpdf -- disk fill DoS vulnerability

2005-08-0900:00:00
vuxml.freebsd.org
18

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.001

Percentile

28.4%

xpdf is vulnerable to a denial of service vulnerability
which can cause xpdf to create an infinitely large file,
thereby filling up the /tmp partition, when opening a
specially crafted PDF file.
Note that several applications contains an embedded version
of xpdf, therefor making them the vulnerable to the same
DoS. In CUPS this vulnerability would cause the pdftops
filter to crash.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchxpdf< 3.00_7UNKNOWN
FreeBSDanynoarchkdegraphics< 3.4.2UNKNOWN
FreeBSDanynoarchgpdf< 2.10.0_2UNKNOWN
FreeBSDanynoarchcups-base< 1.1.23.0_5UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.001

Percentile

28.4%