Lucene search

K
ubuntuUbuntuUSN-236-2
HistoryJan 09, 2006 - 12:00 a.m.

xpdf vulnerabilities in kword, kpdf

2006-01-0900:00:00
ubuntu.com
36

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.2 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.8%

Releases

  • Ubuntu 5.10
  • Ubuntu 5.04

Details

USN-236-1 fixed several vulnerabilities in xpdf. kpdf and kword
contain copies of xpdf code and are thus vulnerable to the same
issues.

For reference, this is the original advisory:

Chris Evans discovered several integer overflows in the XPDF code,
which is present in xpdf, the Poppler library, and tetex-bin. By
tricking an user into opening a specially crafted PDF file, an
attacker could exploit this to execute arbitrary code with the
privileges of the application that processes the document.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.2 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.8%