CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
73.7%
It was discovered that PDFResurrect was incorrectly handling corrupted PDF
files. An attacker could possibly use this issue to cause a buffer overflow,
resulting in a denial of service, or arbitrary code execution. This issue
only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2019-14267)
It was discovered that PDFResurrect incorrectly handled memory when loading
PDF pages. An attacker could possibly use this issue to cause a heap
buffer overflow, resulting in a denial of service, or arbitrary code execution.
This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM.
(CVE-2019-14934)
It was discovered that PDFResurrect was incorrectly validating header data in
input PDF files. An attacker could possibly use this issue to cause a heap
buffer overflow, resulting in a denial of service, or arbitrary code execution.
This issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM.
(CVE-2020-20740)
Carter Yagemann discovered that PDFResurrect incorrectly handled certain memory
operations during PDF summary generation. An attacker could use this to
cause out-of-bounds writes, resulting in a denial of service (system crash)
or arbitrary code execution. This issue only affected Ubuntu 18.04 ESM and
Ubuntu 20.04 ESM. (CVE-2020-9549)
It was discovered that PDFResurrect was incorrectly processing data when
performing trailer search operations. An attacker could possibly use this issue
to cause an infinite loop, resulting in a denial of service. (CVE-2021-3508)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 22.04 | noarch | pdfresurrect | < 0.22-2ubuntu0.1~esm1 | UNKNOWN |
Ubuntu | 22.04 | noarch | pdfresurrect | < 0.22-2 | UNKNOWN |
Ubuntu | 22.04 | noarch | pdfresurrect-dbgsym | < 0.22-2 | UNKNOWN |
Ubuntu | 20.04 | noarch | pdfresurrect | < 0.19-1ubuntu0.1~esm1 | UNKNOWN |
Ubuntu | 20.04 | noarch | pdfresurrect | < 0.19-1 | UNKNOWN |
Ubuntu | 20.04 | noarch | pdfresurrect-dbgsym | < 0.19-1 | UNKNOWN |
Ubuntu | 18.04 | noarch | pdfresurrect | < 0.14-1ubuntu0.1~esm1 | UNKNOWN |
Ubuntu | 18.04 | noarch | pdfresurrect | < 0.14-1 | UNKNOWN |
Ubuntu | 18.04 | noarch | pdfresurrect-dbgsym | < 0.14-1 | UNKNOWN |
Ubuntu | 16.04 | noarch | pdfresurrect | < 0.12-6ubuntu0.2+esm1 | UNKNOWN |
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
73.7%