Information on source package xpdf

Available versions

ReleaseVersion
jessie3.03-17
stretch3.04-4
buster3.04-13
sid3.04-13

Open unimportant issues

BugjessiestretchbustersidDescription
CVE-2018-8107vulnerablevulnerablevulnerablevulnerableThe JPXStream::close function in JPXStream.cc in xpdf 4.00 allows ...
CVE-2018-8106vulnerablevulnerablevulnerablevulnerableThe JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 ...
CVE-2018-8105vulnerablevulnerablevulnerablevulnerableThe JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows ...
CVE-2018-8104vulnerablevulnerablevulnerablevulnerableThe BufStream::lookChar function in Stream.cc in xpdf 4.00 allows ...
CVE-2018-8103vulnerablevulnerablevulnerablevulnerableThe JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf ...
CVE-2018-8102vulnerablevulnerablevulnerablevulnerableThe JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf ...
CVE-2018-8101vulnerablevulnerablevulnerablevulnerableThe JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf ...
CVE-2018-8100vulnerablevulnerablevulnerablevulnerableThe JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 ...
CVE-2018-7455vulnerablevulnerablevulnerablevulnerableAn out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in ...
CVE-2018-7454vulnerablevulnerablevulnerablevulnerableA NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf ...
CVE-2018-7453vulnerablevulnerablevulnerablevulnerableInfinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 ...
CVE-2018-7452vulnerablevulnerablevulnerablevulnerableA NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in ...
CVE-2018-7175vulnerablevulnerablevulnerablevulnerableAn issue was discovered in xpdf 4.00. A NULL pointer dereference in ...
CVE-2018-7174vulnerablevulnerablevulnerablevulnerableAn issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref ...
CVE-2018-7173vulnerablevulnerablevulnerablevulnerableA large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an ...
CVE-2018-18459vulnerablevulnerablevulnerablevulnerableThe function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows ...
CVE-2018-18458vulnerablevulnerablevulnerablevulnerableThe function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows ...
CVE-2018-18457vulnerablevulnerablevulnerablevulnerableThe function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows ...
CVE-2018-18456vulnerablevulnerablevulnerablevulnerableThe function Object::isName() in Object.h (called from ...
CVE-2018-18455vulnerablevulnerablevulnerablevulnerableThe GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote ...
CVE-2018-18454vulnerablevulnerablevulnerablevulnerableCCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote ...
CVE-2018-16369vulnerablevulnerablevulnerablevulnerableXRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a ...
CVE-2018-16368vulnerablevulnerablevulnerablevulnerableSplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows ...
CVE-2018-11033vulnerablevulnerablevulnerablevulnerableThe DCTStream::readHuffSym function in Stream.cc in the DCT decoder in ...
CVE-2013-4472vulnerablevulnerablevulnerablevulnerableThe openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 ...
CVE-2010-0207vulnerablevulnerablevulnerablevulnerablexpdf: XRef table parsing infinite loop
CVE-2010-0206vulnerablevulnerablevulnerablevulnerablexpdf: Invalid pointer dereference by processing JBIG2 PDF stream objects

Resolved issues

BugDescription
CVE-2018-18651An issue was discovered in Xpdf 4.00. catalog->getNumPages() in ...
CVE-2018-18650An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc ...
CVE-2012-2142Insufficient sanitization of escape sequences in the error message
CVE-2011-2902zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and ...
CVE-2011-1554Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before ...
CVE-2011-1553Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in ...
CVE-2011-1552t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and ...
CVE-2011-0764t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and ...
CVE-2010-4654Malformed commands may cause corruption of the internal stack
CVE-2010-4653integer overflow when parsing CharCodes for fonts
CVE-2010-3704The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser ...
CVE-2010-3703The PostScriptFunction::PostScriptFunction function in ...
CVE-2010-3702The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, ...
CVE-2009-4035The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf ...
CVE-2009-3609Integer overflow in the ImageStream::ImageStream function in Stream.cc ...
CVE-2009-3608Integer overflow in the ObjectStream::ObjectStream function in XRef.cc ...
CVE-2009-3606Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf ...
CVE-2009-3604The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before ...
CVE-2009-3603Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf ...
CVE-2009-1188Integer overflow in the JBIG2 decoding feature in the ...
CVE-2009-1183The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and ...
CVE-2009-1182Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and ...
CVE-2009-1181The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, ...
CVE-2009-1180The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, ...
CVE-2009-1179Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, ...
CVE-2009-1144Untrusted search path vulnerability in the Gentoo package of Xpdf ...
CVE-2009-0800Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 ...
CVE-2009-0799The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, ...
CVE-2009-0195Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, ...
CVE-2009-0166The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, ...
CVE-2009-0165Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as ...
CVE-2009-0147Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and ...
CVE-2009-0146Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and ...
CVE-2008-2950The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and ...
CVE-2008-1693The CairoFont::create function in CairoFontEngine.cc in Poppler, ...
CVE-2007-5393Heap-based buffer overflow in the CCITTFaxStream::lookChar method in ...
CVE-2007-5392Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in ...
CVE-2007-4352Array index error in the DCTStream::readProgressiveDataUnit method in ...
CVE-2007-3387Integer overflow in the StreamPredictor::StreamPredictor function in ...
CVE-2007-0104The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 ...
CVE-2006-1244Unspecified vulnerability in certain versions of xpdf after 3.00, as ...
CVE-2006-0301Heap-based buffer overflow in Splash.cc in xpdf, as used in other ...
CVE-2005-3628Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in ...
CVE-2005-3627Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, ...
CVE-2005-3626Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, ...
CVE-2005-3625Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, ...
CVE-2005-3624The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, ...
CVE-2005-3193Heap-based buffer overflow in the JPXStream::readCodestream function ...
CVE-2005-3192Heap-based buffer overflow in the StreamPredictor function in Xpdf ...
CVE-2005-3191Multiple heap-based buffer overflows in the (1) ...
CVE-2005-2097xpdf and kpdf do not properly validate the "loca" table in PDF files, ...
CVE-2005-0206The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 ...
CVE-2005-0064Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc ...
CVE-2004-1125Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, ...
CVE-2004-0889Multiple integer overflows in xpdf 3.0, and other packages that use ...
CVE-2004-0888Multiple integer overflows in xpdf 2.0 and 3.0, and other packages ...
CVE-2003-0434Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 ...
CVE-2002-1384Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, ...

Security announcements

DSA / DLADescription
DSA-2135-1xpdf - several vulnerabilities
DSA-2028-1xpdf - several vulnerabilities
DSA-1790-1xpdf - multiple vulnerabilities
DSA-1790-1xpdf - multiple vulnerabilities
DSA-1548-1xpdf
DSA-1537-1xpdf
DSA-1347-1xpdf
DSA-1347-1xpdf
DSA-984-1xpdf - several
DSA-971-1xpdf - buffer overflow
DSA-931-1xpdf - buffer overflows
DSA-931-1xpdf - buffer overflows
DSA-648-1xpdf - buffer overflow
DSA-619-1xpdf - buffer overflow
DSA-581-1xpdf - integer overflows
DSA-226xpdf-i - integer overflow
DSA-222xpdf - integer overflow

Search for package or bug name: Reporting problems