CVE-2005-0206

NameCVE-2005-0206
DescriptionThe patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cups (PTS)bullseye2.3.3op2-3+deb11u8fixed
bullseye (security)2.3.3op2-3+deb11u9fixed
bookworm, bookworm (security)2.4.2-3+deb12u8fixed
sid, trixie2.4.10-2fixed
xpdf (PTS)bullseye3.04+git20210103-3fixed
bookworm3.04+git20220601-1fixed
sid, trixie3.04+git20240613-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cupssource(unstable)1.1.22-7
cupsyssource(unstable)1.1.22-7
gpdfsource(unstable)(not affected)
kdegraphicssource(unstable)(not affected)
pdftohtmlsource(unstable)(not affected)
tetex-binsource(unstable)(not affected)
xpdfsource(unstable)(not affected)

Notes

- xpdf <not-affected> (Initial Debian fix was already correct)
- gpdf <not-affected> (Initial Debian fix was already correct)
- kdegraphics <not-affected> (Initial Debian fix was already correct)
- tetex-bin <not-affected> (Initial Debian fix was already correct)
- pdftohtml <not-affected> (Initial Debian fix was already correct)
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135393
cupsys uses an external xpdf now.

Search for package or bug name: Reporting problems