CVE-2005-3628

NameCVE-2005-3628
DescriptionBuffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-931-1, DSA-932-1, DSA-936-1, DSA-937-1, DSA-938-1, DSA-940-1, DSA-950-1, DSA-961-1, DSA-962-1, DTSA-28-1
NVD severityhigh
Debian Bugs342286, 342294

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cups (PTS)stretch2.2.1-8+deb9u6fixed
stretch (security)2.2.1-8+deb9u2fixed
buster2.2.10-6+deb10u3fixed
bullseye, sid2.3.3-3fixed
libextractor (PTS)stretch (security), stretch1:1.3-4+deb9u3fixed
buster1:1.8-2fixed
bullseye, sid1:1.10-1fixed
xpdf (PTS)stretch3.04-4fixed
sid, buster3.04-13fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cupssource(unstable)1.1.22-7
cupsyssourcewoody1.1.14-5woody14DSA-950-1
cupsyssourcesarge(not affected)DSA-950-1
cupsyssource(unstable)1.1.22-7
gpdfsourcesarge2.8.2-1.2sarge2DSA-940-1
gpdfsourceetch2.10.0-1+etch1DTSA-28-1
gpdfsource(unstable)2.10.0-2342286
kdegraphicssourcesarge4:3.3.2-2sarge3DSA-932-1
kdegraphicssource(unstable)4:3.5.0-3
kofficesourcesarge1:1.3.5-4.sarge.2DSA-938-1
kofficesource(unstable)1:1.4.2-6342294
libextractorsourcesarge0.4.2-2sarge2DSA-936-1
libextractorsource(unstable)0.5.9-1
pdfkit.frameworksourcesarge0.8-2sarge1DSA-961-1
pdfkit.frameworksource(unstable)0.8-4
pdftohtmlsourcesarge0.36-11sarge1DSA-962-1
pdftohtmlsource(unstable)0.36-12
tetex-binsourcewoody1.0.7+20011202-7.7DSA-937-1
tetex-binsourcesarge2.0.2-30sarge4DSA-937-1
tetex-binsource(unstable)3.0-12
xpdfsourcewoody1.00-3.8DSA-931-1
xpdfsourcesarge3.00-13.4DSA-931-1
xpdfsource(unstable)3.01-4

Notes

cupsys switched to an external PDF implementation in 1.1.22-7.
tetex-bin switched to poppler in 3.0-12.

Search for package or bug name: Reporting problems