DescriptionThe patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cups (PTS)bullseye2.3.3op2-3+deb11u6fixed
bullseye (security)2.3.3op2-3+deb11u2fixed
trixie, sid2.4.10-1fixed
xpdf (PTS)bullseye3.04+git20210103-3fixed
trixie, sid3.04+git20240613-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gpdfsource(unstable)(not affected)
kdegraphicssource(unstable)(not affected)
pdftohtmlsource(unstable)(not affected)
tetex-binsource(unstable)(not affected)
xpdfsource(unstable)(not affected)


- xpdf <not-affected> (Initial Debian fix was already correct)
- gpdf <not-affected> (Initial Debian fix was already correct)
- kdegraphics <not-affected> (Initial Debian fix was already correct)
- tetex-bin <not-affected> (Initial Debian fix was already correct)
- pdftohtml <not-affected> (Initial Debian fix was already correct)
cupsys uses an external xpdf now.

Search for package or bug name: Reporting problems