10

CVE-2004-0888

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Easy Software Products ≫ Cups Version 1.0.4
Easy Software Products ≫ Cups Version 1.0.4_8
Easy Software Products ≫ Cups Version 1.1.1
Easy Software Products ≫ Cups Version 1.1.4
Easy Software Products ≫ Cups Version 1.1.4_2
Easy Software Products ≫ Cups Version 1.1.4_3
Easy Software Products ≫ Cups Version 1.1.4_5
Easy Software Products ≫ Cups Version 1.1.6
Easy Software Products ≫ Cups Version 1.1.7
Easy Software Products ≫ Cups Version 1.1.10
Easy Software Products ≫ Cups Version 1.1.12
Easy Software Products ≫ Cups Version 1.1.13
Easy Software Products ≫ Cups Version 1.1.14
Easy Software Products ≫ Cups Version 1.1.15
Easy Software Products ≫ Cups Version 1.1.16
Easy Software Products ≫ Cups Version 1.1.17
Easy Software Products ≫ Cups Version 1.1.18
Easy Software Products ≫ Cups Version 1.1.19
Easy Software Products ≫ Cups Version 1.1.19_rc5
Easy Software Products ≫ Cups Version 1.1.20
Gnome ≫ Gpdf Version 0.112
Gnome ≫ Gpdf Version 0.131
Kde ≫ Koffice Version 1.3
Kde ≫ Koffice Version 1.3.1
Kde ≫ Koffice Version 1.3.2
Kde ≫ Koffice Version 1.3.3
Kde ≫ Koffice Version 1.3_beta1
Kde ≫ Koffice Version 1.3_beta2
Kde ≫ Koffice Version 1.3_beta3
Kde ≫ Kpdf Version 3.2
Pdftohtml ≫ Pdftohtml Version 0.32a
Pdftohtml ≫ Pdftohtml Version 0.32b
Pdftohtml ≫ Pdftohtml Version 0.33
Pdftohtml ≫ Pdftohtml Version 0.33a
Pdftohtml ≫ Pdftohtml Version 0.34
Pdftohtml ≫ Pdftohtml Version 0.35
Pdftohtml ≫ Pdftohtml Version 0.36
Tetex ≫ Tetex Version 1.0.7
Tetex ≫ Tetex Version 2.0
Tetex ≫ Tetex Version 2.0.1
Tetex ≫ Tetex Version 2.0.2
Xpdf ≫ Xpdf Version 0.90
Xpdf ≫ Xpdf Version 0.91
Xpdf ≫ Xpdf Version 0.92
Xpdf ≫ Xpdf Version 0.93
Xpdf ≫ Xpdf Version 1.0
Xpdf ≫ Xpdf Version 1.0a
Xpdf ≫ Xpdf Version 1.1
Xpdf ≫ Xpdf Version 2.0
Xpdf ≫ Xpdf Version 2.1
Xpdf ≫ Xpdf Version 2.3
Xpdf ≫ Xpdf Version 3.0
Debian ≫ Debian Linux Version 3.0
Debian ≫ Debian Linux Version 3.0 Edition alpha
Debian ≫ Debian Linux Version 3.0 Edition arm
Debian ≫ Debian Linux Version 3.0 Edition hppa
Debian ≫ Debian Linux Version 3.0 Edition ia-32
Debian ≫ Debian Linux Version 3.0 Edition ia-64
Debian ≫ Debian Linux Version 3.0 Edition m68k
Debian ≫ Debian Linux Version 3.0 Edition mips
Debian ≫ Debian Linux Version 3.0 Edition mipsel
Debian ≫ Debian Linux Version 3.0 Edition ppc
Debian ≫ Debian Linux Version 3.0 Edition s-390
Debian ≫ Debian Linux Version 3.0 Edition sparc
Kde ≫ Kde Version 3.2
Kde ≫ Kde Version 3.2.1
Kde ≫ Kde Version 3.2.2
Kde ≫ Kde Version 3.2.3
Kde ≫ Kde Version 3.3
Kde ≫ Kde Version 3.3.1
Redhat ≫ Enterprise Linux Version 2.1 Edition advanced_server
Redhat ≫ Enterprise Linux Version 2.1 Edition advanced_server_ia64
Redhat ≫ Enterprise Linux Version 2.1 Edition enterprise_server
Redhat ≫ Enterprise Linux Version 2.1 Edition enterprise_server_ia64
Redhat ≫ Enterprise Linux Version 2.1 Edition workstation
Redhat ≫ Enterprise Linux Version 2.1 Edition workstation_ia64
Redhat ≫ Enterprise Linux Version 3.0 Edition advanced_server
Redhat ≫ Enterprise Linux Version 3.0 Edition enterprise_server
Redhat ≫ Enterprise Linux Version 3.0 Edition workstation_server
Redhat ≫ Fedora Core Version core_2.0
Redhat ≫ Linux Advanced Workstation Version 2.1 Edition ia64
Redhat ≫ Linux Advanced Workstation Version 2.1 Edition itanium_processor
Suse ≫ Suse Linux Version 8.0
Suse ≫ Suse Linux Version 8.1
Suse ≫ Suse Linux Version 8.2
Suse ≫ Suse Linux Version 9.0
Suse ≫ Suse Linux Version 9.0 Edition x86_64
Suse ≫ Suse Linux Version 9.1
Suse ≫ Suse Linux Version 9.2
Ubuntu ≫ Ubuntu Linux Version 4.1 Edition ia64
Ubuntu ≫ Ubuntu Linux Version 4.1 Edition ppc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.33% 0.947
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.redhat.com/support/errata/RHSA-2005-354.html
http://www.redhat.com/support/errata/RHSA-2005-066.html
https://bugzilla.fedora.us/show_bug.cgi?id=2353
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000886
http://marc.info/?l=bugtraq&m=109880927526773&w=2
http://marc.info/?l=bugtraq&m=110815379627883&w=2
http://www.debian.org/security/2004/dsa-573
http://www.debian.org/security/2004/dsa-581
http://www.debian.org/security/2004/dsa-599
http://www.gentoo.org/security/en/glsa/glsa-200410-20.xml
http://www.gentoo.org/security/en/glsa/glsa-200410-30.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:113
http://www.mandriva.com/security/advisories?name=MDKSA-2004:114
http://www.mandriva.com/security/advisories?name=MDKSA-2004:115
http://www.mandriva.com/security/advisories?name=MDKSA-2004:116
http://www.redhat.com/support/errata/RHSA-2004-543.html
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-592.html
http://www.securityfocus.com/bid/11501
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/17818
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9714
https://www.ubuntu.com/usn/usn-9-1/