Unknown
CVE-2005-3625
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka “Infinite CPU spins.”
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- cups 1.1.22,
- cups 1.1.22 rc1,
- cups 1.1.23,
- cups 1.1.23 rc1,
- debian linux 3.0,
- debian linux 3.1,
- enterprise linux 2.1,
- enterprise linux 3.0,
- enterprise linux 4.0,
- enterprise linux desktop 3.0,
- enterprise linux desktop 4.0,
- fedora core core 1.0,
- fedora core core 2.0,
- fedora core core 3.0,
- fedora core core 4.0,
- kdegraphics 3.2,
- kdegraphics 3.4.3,
- koffice 1.4,
- koffice 1.4.1,
- koffice 1.4.2,
- kpdf 3.2,
- kpdf 3.4.3,
- kword 1.4.2,
- libextractor,
- linux,
- linux 10.0,
- linux 7.3,
- linux 9.0,
- linux advanced workstation 2.1,
- mandrake linux 10.1,
- mandrake linux 10.2,
- mandrake linux 2006,
- mandrake linux corporate server 2.1,
- mandrake linux corporate server 3.0,
- openserver 5.0.7,
- openserver 6.0,
- poppler 0.4.2,
- propack 3.0,
- secure linux 2.0,
- secure linux 2.2,
- secure linux 3.0,
- slackware linux 10.0,
- slackware linux 10.1,
- slackware linux 10.2,
- slackware linux 9.0,
- slackware linux 9.1,
- suse linux 1.0,
- suse linux 10.0,
- suse linux 9.0,
- suse linux 9.1,
- suse linux 9.2,
- suse linux 9.3,
- tetex 1.0.7,
- tetex 2.0,
- tetex 2.0.1,
- tetex 2.0.2,
- tetex 3.0,
- turbolinux 10,
- turbolinux appliance server 1.0 hosting edition,
- turbolinux appliance server 1.0 workgroup edition,
- turbolinux desktop 10.0,
- turbolinux fuji,
- turbolinux home,
- turbolinux multimedia,
- turbolinux personal,
- turbolinux server 10.0,
- turbolinux server 10.0 x86,
- turbolinux server 8.0,
- turbolinux workstation 8.0,
- ubuntu linux 4.1,
- ubuntu linux 5.04,
- ubuntu linux 5.10,
- xpdf 3.0
References
Advisory
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: