7.6

CVE-2006-1244

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc.  NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed.  Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.

Data is provided by the National Vulnerability Database (NVD)
GnomeGpdf Version2.8.2
LibextractorLibextractor Version0.3.6
LibextractorLibextractor Version0.3.7
LibextractorLibextractor Version0.3.8
LibextractorLibextractor Version0.3.9
LibextractorLibextractor Version0.3.11
LibextractorLibextractor Version0.4
LibextractorLibextractor Version0.4.1
LibextractorLibextractor Version0.4.2
LibextractorLibextractor Version0.5
XpdfXpdf Version0.90
XpdfXpdf Version0.91
XpdfXpdf Version0.92
XpdfXpdf Version0.93
XpdfXpdf Version1.0
XpdfXpdf Version1.0a
XpdfXpdf Version1.1
XpdfXpdf Version2.0
XpdfXpdf Version2.1
XpdfXpdf Version2.2
XpdfXpdf Version2.3
XpdfXpdf Version3.0
XpdfXpdf Version3.0.1
XpdfXpdf Version3.0.1_pl1
XpdfXpdf Version3.0_pl2
XpdfXpdf Version3.0_pl3
DebianDebian Linux Version3.1
DebianDebian Linux Version3.1 Editionalpha
DebianDebian Linux Version3.1 Editionamd64
DebianDebian Linux Version3.1 Editionarm
DebianDebian Linux Version3.1 Editionhppa
DebianDebian Linux Version3.1 Editionia-32
DebianDebian Linux Version3.1 Editionia-64
DebianDebian Linux Version3.1 Editionm68k
DebianDebian Linux Version3.1 Editionmips
DebianDebian Linux Version3.1 Editionmipsel
DebianDebian Linux Version3.1 Editionppc
DebianDebian Linux Version3.1 Editions-390
DebianDebian Linux Version3.1 Editionsparc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.47% 0.865
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C