Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2006-1244

Disclosure Date: March 15, 2006
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, © pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • debian,
  • gnome,
  • libextractor,
  • xpdf

Products

  • debian linux 3.1,
  • gpdf 2.8.2,
  • libextractor 0.3.11,
  • libextractor 0.3.6,
  • libextractor 0.3.7,
  • libextractor 0.3.8,
  • libextractor 0.3.9,
  • libextractor 0.4,
  • libextractor 0.4.1,
  • libextractor 0.4.2,
  • libextractor 0.5,
  • xpdf 0.90,
  • xpdf 0.91,
  • xpdf 0.92,
  • xpdf 0.93,
  • xpdf 1.0,
  • xpdf 1.0a,
  • xpdf 1.1,
  • xpdf 2.0,
  • xpdf 2.1,
  • xpdf 2.2,
  • xpdf 2.3,
  • xpdf 3.0,
  • xpdf 3.0 pl2,
  • xpdf 3.0 pl3,
  • xpdf 3.0.1,
  • xpdf 3.0.1 pl1
Technical Analysis