Vulnerability Description
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ascii | Ptex | 3.1.4 |
| Cstex | Cstetex | 2.0.2 |
| Easy Software Products | Cups | 1.0.4 |
| Gnome | Gpdf | 0.110 |
| Kde | Koffice | 1.3 |
| Kde | Kpdf | 3.2 |
| Pdftohtml | Pdftohtml | 0.32a |
| Sgi | Propack | 3.0 |
| Tetex | Tetex | 1.0.6 |
| Xpdf | Xpdf | 0.90 |
| Sgi | Advanced Linux Environment | 3.0 |
| Debian | Debian Linux | 3.0 |
| Gentoo | Linux | All versions |
| Kde | Kde | 3.2 |
| Mandrakesoft | Mandrake Linux Corporate Server | 3.0 |
| Redhat | Enterprise Linux | 2.1 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Fedora Core | core_1.0 |
| Redhat | Linux | 9.0 |
| Redhat | Linux Advanced Workstation | 2.1 |
References
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:041
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:042
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:043
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:044
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:052
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:056
- http://www.redhat.com/support/errata/RHSA-2005-034.html
- http://www.redhat.com/support/errata/RHSA-2005-053.html
- http://www.redhat.com/support/errata/RHSA-2005-057.html
- http://www.redhat.com/support/errata/RHSA-2005-132.html
- http://www.redhat.com/support/errata/RHSA-2005-213.htmlPatchVendor Advisory
- http://www.securityfocus.com/bid/11501PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17818
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:041
FAQ
What is CVE-2005-0206?
CVE-2005-0206 is a vulnerability with a CVSS score of 7.5 (HIGH). The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users e...
How severe is CVE-2005-0206?
CVE-2005-0206 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0206?
Check the references section above for vendor advisories and patch information. Affected products include: Ascii Ptex, Cstex Cstetex, Easy Software Products Cups, Gnome Gpdf, Kde Koffice.