CVE-2005-0206

NameCVE-2005-0206
DescriptionThe patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cups (PTS)stretch2.2.1-8+deb9u6fixed
stretch (security)2.2.1-8+deb9u2fixed
buster2.2.10-6+deb10u4fixed
bullseye2.3.3op2-3+deb11u1fixed
bookworm, sid2.3.3op2-7fixed
xpdf (PTS)stretch3.04-4fixed
buster3.04-13fixed
bookworm, bullseye, sid3.04+git20210103-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cupssource(unstable)1.1.22-7
cupsyssource(unstable)1.1.22-7
gpdfsource(unstable)(not affected)
kdegraphicssource(unstable)(not affected)
pdftohtmlsource(unstable)(not affected)
tetex-binsource(unstable)(not affected)
xpdfsource(unstable)(not affected)

Notes

- xpdf <not-affected> (Initial Debian fix was already correct)
- gpdf <not-affected> (Initial Debian fix was already correct)
- kdegraphics <not-affected> (Initial Debian fix was already correct)
- tetex-bin <not-affected> (Initial Debian fix was already correct)
- pdftohtml <not-affected> (Initial Debian fix was already correct)
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135393
cupsys uses an external xpdf now.

Search for package or bug name: Reporting problems