Vulnerability Description
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gpdf | 2.8.2 |
| Libextractor | Libextractor | 0.3.6 |
| Xpdf | Xpdf | 0.90 |
| Debian | Debian Linux | 3.1 |
References
- http://secunia.com/advisories/18948PatchVendor Advisory
- http://secunia.com/advisories/19021PatchVendor Advisory
- http://secunia.com/advisories/19065PatchVendor Advisory
- http://secunia.com/advisories/19091PatchVendor Advisory
- http://secunia.com/advisories/19164PatchVendor Advisory
- http://secunia.com/advisories/19364PatchVendor Advisory
- http://secunia.com/advisories/19644PatchVendor Advisory
- http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.frameworkPatch
- http://www.debian.org/security/2006/dsa-1019PatchVendor Advisory
- http://www.debian.org/security/2006/dsa-979PatchVendor Advisory
- http://www.debian.org/security/2006/dsa-982PatchVendor Advisory
- http://www.debian.org/security/2006/dsa-983PatchVendor Advisory
- http://www.debian.org/security/2006/dsa-984PatchVendor Advisory
- http://www.debian.org/security/2006/dsa-998PatchVendor Advisory
- http://www.osvdb.org/23834
FAQ
What is CVE-2006-1244?
CVE-2006-1244 is a vulnerability with a CVSS score of 7.6 (HIGH). Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user...
How severe is CVE-2006-1244?
CVE-2006-1244 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1244?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Gpdf, Libextractor Libextractor, Xpdf Xpdf, Debian Debian Linux.