Description
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Affected products
- conectiva / linux10.0 – 10.0
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.0 – 3.0
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- Debian / debian_linux3.1 – 3.1
- easy_software_products / cups1.1.22_rc1 – 1.1.22_rc1
- easy_software_products / cups1.1.23 – 1.1.23
- easy_software_products / cups1.1.23_rc1 – 1.1.23_rc1
- easy_software_products / cups1.1.22 – 1.1.22
- gentoo / linux
- KDE / kdegraphics3.4.3 – 3.4.3
- KDE / kdegraphics3.2 – 3.2
- KDE / koffice1.4 – 1.4
- KDE / koffice1.4.2 – 1.4.2
- KDE / koffice1.4.1 – 1.4.1
- KDE / kpdf3.2 – 3.2
- KDE / kpdf3.4.3 – 3.4.3
- KDE / kword1.4.2 – 1.4.2
- libextractor / libextractor
- mandrakesoft / mandrake_linux10.1 – 10.1
- mandrakesoft / mandrake_linux2006 – 2006
- mandrakesoft / mandrake_linux2006 – 2006
- mandrakesoft / mandrake_linux10.2 – 10.2
- mandrakesoft / mandrake_linux10.2 – 10.2
- mandrakesoft / mandrake_linux10.1 – 10.1
- mandrakesoft / mandrake_linux_corporate_server3.0 – 3.0
- mandrakesoft / mandrake_linux_corporate_server2.1 – 2.1
- mandrakesoft / mandrake_linux_corporate_server2.1 – 2.1
- mandrakesoft / mandrake_linux_corporate_server3.0 – 3.0
- poppler / poppler0.4.2 – 0.4.2
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux_desktop3.0 – 3.0
- RedHat / enterprise_linux_desktop4.0 – 4.0
- RedHat / fedora_corecore_1.0 – core_1.0
- RedHat / fedora_corecore_4.0 – core_4.0
- RedHat / fedora_corecore_3.0 – core_3.0
- RedHat / fedora_corecore_2.0 – core_2.0
- RedHat / linux9.0 – 9.0
- RedHat / linux7.3 – 7.3
- RedHat / linux_advanced_workstation2.1 – 2.1
- RedHat / linux_advanced_workstation2.1 – 2.1
- sco / openserver5.0.7 – 5.0.7
- sco / openserver6.0 – 6.0
- sgi / propack3.0 – 3.0
- slackware / slackware_linux9.1 – 9.1
- slackware / slackware_linux10.0 – 10.0
- slackware / slackware_linux10.1 – 10.1
- slackware / slackware_linux10.2 – 10.2
- slackware / slackware_linux9.0 – 9.0
- SUSE / suse_linux10.0 – 10.0
- SUSE / suse_linux1.0 – 1.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.2 – 9.2
- SUSE / suse_linux9.2 – 9.2
- SUSE / suse_linux9.2 – 9.2
- SUSE / suse_linux9.3 – 9.3
- SUSE / suse_linux9.3 – 9.3
- SUSE / suse_linux9.3 – 9.3
- SUSE / suse_linux10.0 – 10.0
- tetex / tetex2.0.2 – 2.0.2
- tetex / tetex3.0 – 3.0
- tetex / tetex1.0.7 – 1.0.7
- tetex / tetex2.0 – 2.0
- tetex / tetex2.0.1 – 2.0.1
- trustix / secure_linux2.0 – 2.0
- trustix / secure_linux2.2 – 2.2
- trustix / secure_linux3.0 – 3.0
- turbolinux / turbolinux10 – 10
- turbolinux / turbolinuxfuji – fuji
- turbolinux / turbolinux_appliance_server1.0_workgroup_edition – 1.0_workgroup_edition
- turbolinux / turbolinux_appliance_server1.0_hosting_edition – 1.0_hosting_edition
- turbolinux / turbolinux_desktop10.0 – 10.0
- turbolinux / turbolinux_home
- turbolinux / turbolinux_multimedia
- turbolinux / turbolinux_personal
- turbolinux / turbolinux_server10.0 – 10.0
- turbolinux / turbolinux_server10.0_x86 – 10.0_x86
- turbolinux / turbolinux_server8.0 – 8.0
- turbolinux / turbolinux_workstation8.0 – 8.0
- Ubuntu / ubuntu_linux5.10 – 5.10
- Ubuntu / ubuntu_linux5.10 – 5.10
- Ubuntu / ubuntu_linux5.04 – 5.04
- Ubuntu / ubuntu_linux5.04 – 5.04
- Ubuntu / ubuntu_linux5.10 – 5.10
- Ubuntu / ubuntu_linux5.04 – 5.04
- Ubuntu / ubuntu_linux4.1 – 4.1
- Ubuntu / ubuntu_linux4.1 – 4.1
- Xpdf / Xpdf3.0 – 3.0
References
- MISChttp://www.securityfocus.com/bid/16143
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-932
- VENDOR_ADVISORYhttp://secunia.com/advisories/18349
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9575
- VENDOR_ADVISORYhttp://secunia.com/advisories/18147
- MISCftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt
- MISChttp://scary.beasts.org/security/CESA-2005-003.txt
- MISChttp://www.kde.org/info/security/advisory-20051207-2.txt
- VENDOR_ADVISORYhttp://secunia.com/advisories/18679
- VENDOR_ADVISORYhttp://secunia.com/advisories/18312
- VENDOR_ADVISORYhttp://secunia.com/advisories/18644
- VENDOR_ADVISORYhttps://usn.ubuntu.com/236-1/
- VENDOR_ADVISORYhttp://secunia.com/advisories/18425
- VENDOR_ADVISORYhttp://secunia.com/advisories/18373
- VENDOR_ADVISORYhttp://secunia.com/advisories/18303
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-931
- VENDOR_ADVISORYhttp://secunia.com/advisories/18554
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:003
- VENDOR_ADVISORYhttp://secunia.com/advisories/19230
- MISChttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:012
- VENDOR_ADVISORYhttp://www.debian.org/security/2006/dsa-962
- MISChttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00010.html
- MISChttp://www.redhat.com/support/errata/RHSA-2006-0163.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-937
- VENDOR_ADVISORYhttp://secunia.com/advisories/18398
- MISChttp://www.securityfocus.com/archive/1/427053/100/0/threaded
- MISChttp://www.trustix.org/errata/2006/0002/
- MAILING_LISThttp://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2006/dsa-936
- MISChttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00031.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/18329
- VENDOR_ADVISORYhttp://secunia.com/advisories/18463
- VENDOR_ADVISORYhttp://secunia.com/advisories/18642
- VENDOR_ADVISORYhttp://secunia.com/advisories/18674
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:005
- VENDOR_ADVISORYhttp://secunia.com/advisories/18313
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20051201-01-U
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
- VENDOR_ADVISORYhttp://secunia.com/advisories/18448
- VENDOR_ADVISORYhttp://secunia.com/advisories/18436
- VENDOR_ADVISORYhttp://secunia.com/advisories/18428
- VENDOR_ADVISORYhttp://secunia.com/advisories/18380
- VENDOR_ADVISORYhttp://secunia.com/advisories/18423
- VENDOR_ADVISORYhttp://secunia.com/advisories/18416
- MISChttp://rhn.redhat.com/errata/RHSA-2006-0177.html
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2280
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200601-02.xml
- VENDOR_ADVISORYhttp://secunia.com/advisories/18335
- VENDOR_ADVISORYhttp://secunia.com/advisories/18407
- VENDOR_ADVISORYhttp://secunia.com/advisories/18332
- VENDOR_ADVISORYhttp://secunia.com/advisories/18517
- VENDOR_ADVISORYhttp://secunia.com/advisories/18582
- VENDOR_ADVISORYhttp://secunia.com/advisories/18534
- MISChttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/24023
- VENDOR_ADVISORYhttp://secunia.com/advisories/18908
- MISChttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00011.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/25729
- VENDOR_ADVISORYhttp://secunia.com/advisories/18414
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:006
- VENDOR_ADVISORYhttp://secunia.com/advisories/18338
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:008
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20060201-01-U
- MISChttp://www.redhat.com/support/errata/RHSA-2006-0160.html
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:010
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-940
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:004
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/0047
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200601-17.xml
- VENDOR_ADVISORYhttp://secunia.com/advisories/18389
- MISChttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747
- VENDOR_ADVISORYhttp://secunia.com/advisories/19377
- MISChttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00030.html
- MISChttp://www.securityfocus.com/archive/1/427990/100/0/threaded
- VENDOR_ADVISORYhttp://www.debian.org/security/2006/dsa-961
- VENDOR_ADVISORYhttp://secunia.com/advisories/18675
- VENDOR_ADVISORYhttp://secunia.com/advisories/18913
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-938
- VENDOR_ADVISORYhttp://secunia.com/advisories/18334
- VENDOR_ADVISORYhttp://secunia.com/advisories/18375
- VENDOR_ADVISORYhttp://www.debian.org/security/2006/dsa-950
- VENDOR_ADVISORYhttp://secunia.com/advisories/18387
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:011
- VENDOR_ADVISORYhttp://secunia.com/advisories/18385