Vulnerability Description
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easy Software Products | Cups | 1.0.4 |
| Gnome | Gpdf | 0.112 |
| Kde | Koffice | 1.3 |
| Kde | Kpdf | 3.2 |
| Pdftohtml | Pdftohtml | 0.32a |
| Tetex | Tetex | 1.0.7 |
| Xpdf | Xpdf | 0.90 |
| Debian | Debian Linux | 3.0 |
| Gentoo | Linux | All versions |
| Kde | Kde | 3.2 |
| Redhat | Enterprise Linux | 2.1 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Fedora Core | core_2.0 |
| Redhat | Linux Advanced Workstation | 2.1 |
| Suse | Suse Linux | 8.0 |
| Ubuntu | Ubuntu Linux | 4.1 |
References
- http://marc.info/?l=bugtraq&m=109880927526773&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200410-20.xmlPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:113
- http://www.securityfocus.com/bid/11501
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17819
- http://marc.info/?l=bugtraq&m=109880927526773&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200410-20.xmlPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:113
- http://www.securityfocus.com/bid/11501
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17819
FAQ
What is CVE-2004-0889?
CVE-2004-0889 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different...
How severe is CVE-2004-0889?
CVE-2004-0889 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0889?
Check the references section above for vendor advisories and patch information. Affected products include: Easy Software Products Cups, Gnome Gpdf, Kde Koffice, Kde Kpdf, Pdftohtml Pdftohtml.