cvelist/2005/3xxx/CVE-2005-3191.json
2018-10-19 11:05:17 -04:00

638 lines
21 KiB
JSON

{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2005-3191",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a",
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "n/a"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"name" : "20051205 Multiple Vendor xpdf DCTStream Progressive Heap Overflow",
"refsource" : "IDEFENSE",
"url" : "http://www.idefense.com/application/poi/display?id=343&type=vulnerabilities"
},
{
"name" : "Multiple Vendor xpdf DCTStream Baseline Heap Overflow Vulnerability",
"refsource" : "IDEFENSE",
"url" : "http://www.idefense.com/application/poi/display?id=342&type=vulnerabilities"
},
{
"name" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=342289",
"refsource" : "MISC",
"url" : "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=342289"
},
{
"name" : "20051207 [KDE Security Advisory] multiple buffer overflows in kpdf/koffice",
"refsource" : "BUGTRAQ",
"url" : "http://www.securityfocus.com/archive/1/418883/100/0/threaded"
},
{
"name" : "http://www.kde.org/info/security/advisory-20051207-1.txt",
"refsource" : "CONFIRM",
"url" : "http://www.kde.org/info/security/advisory-20051207-1.txt"
},
{
"name" : "http://www.kde.org/info/security/advisory-20051207-2.txt",
"refsource" : "CONFIRM",
"url" : "http://www.kde.org/info/security/advisory-20051207-2.txt"
},
{
"name" : "https://issues.rpath.com/browse/RPL-1609",
"refsource" : "CONFIRM",
"url" : "https://issues.rpath.com/browse/RPL-1609"
},
{
"name" : "DSA-931",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2005/dsa-931"
},
{
"name" : "DSA-932",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2005/dsa-932"
},
{
"name" : "DSA-937",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2005/dsa-937"
},
{
"name" : "DSA-938",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2005/dsa-938"
},
{
"name" : "DSA-940",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2005/dsa-940"
},
{
"name" : "DSA-936",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2006/dsa-936"
},
{
"name" : "DSA-950",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2006/dsa-950"
},
{
"name" : "DSA-961",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2006/dsa-961"
},
{
"name" : "DSA-962",
"refsource" : "DEBIAN",
"url" : "http://www.debian.org/security/2006/dsa-962"
},
{
"name" : "FEDORA-2005-1141",
"refsource" : "FEDORA",
"url" : "http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00036.html"
},
{
"name" : "FEDORA-2005-1142",
"refsource" : "FEDORA",
"url" : "http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00037.html"
},
{
"name" : "FEDORA-2005-1126",
"refsource" : "FEDORA",
"url" : "http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00015.html"
},
{
"name" : "FEDORA-2005-1127",
"refsource" : "FEDORA",
"url" : "http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00016.html"
},
{
"name" : "FLSA:175404",
"refsource" : "FEDORA",
"url" : "http://www.securityfocus.com/archive/1/427990/100/0/threaded"
},
{
"name" : "FLSA-2006:176751",
"refsource" : "FEDORA",
"url" : "http://www.securityfocus.com/archive/1/427053/100/0/threaded"
},
{
"name" : "GLSA-200512-08",
"refsource" : "GENTOO",
"url" : "http://www.gentoo.org/security/en/glsa/glsa-200512-08.xml"
},
{
"name" : "GLSA-200601-02",
"refsource" : "GENTOO",
"url" : "http://www.gentoo.org/security/en/glsa/glsa-200601-02.xml"
},
{
"name" : "MDKSA-2006:010",
"refsource" : "MANDRAKE",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:010"
},
{
"name" : "MDKSA-2006:003",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:003"
},
{
"name" : "MDKSA-2006:004",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:004"
},
{
"name" : "MDKSA-2006:005",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:005"
},
{
"name" : "MDKSA-2006:006",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:006"
},
{
"name" : "MDKSA-2006:008",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:008"
},
{
"name" : "MDKSA-2006:012",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:012"
},
{
"name" : "MDKSA-2006:011",
"refsource" : "MANDRIVA",
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:011"
},
{
"name" : "RHSA-2005:840",
"refsource" : "REDHAT",
"url" : "http://www.redhat.com/support/errata/RHSA-2005-840.html"
},
{
"name" : "RHSA-2005:867",
"refsource" : "REDHAT",
"url" : "http://www.redhat.com/support/errata/RHSA-2005-867.html"
},
{
"name" : "RHSA-2005:878",
"refsource" : "REDHAT",
"url" : "http://www.redhat.com/support/errata/RHSA-2005-878.html"
},
{
"name" : "RHSA-2005:868",
"refsource" : "REDHAT",
"url" : "http://rhn.redhat.com/errata/RHSA-2005-868.html"
},
{
"name" : "RHSA-2006:0160",
"refsource" : "REDHAT",
"url" : "http://www.redhat.com/support/errata/RHSA-2006-0160.html"
},
{
"name" : "SCOSA-2006.15",
"refsource" : "SCO",
"url" : "ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt"
},
{
"name" : "SCOSA-2006.20",
"refsource" : "SCO",
"url" : "ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.20/SCOSA-2006.20.txt"
},
{
"name" : "SCOSA-2006.21",
"refsource" : "SCO",
"url" : "ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.21/SCOSA-2006.21.txt"
},
{
"name" : "20051201-01-U",
"refsource" : "SGI",
"url" : "ftp://patches.sgi.com/support/free/security/advisories/20051201-01-U"
},
{
"name" : "20060101-01-U",
"refsource" : "SGI",
"url" : "ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U"
},
{
"name" : "20060201-01-U",
"refsource" : "SGI",
"url" : "ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U"
},
{
"name" : "SSA:2006-045-04",
"refsource" : "SLACKWARE",
"url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747"
},
{
"name" : "SSA:2006-045-09",
"refsource" : "SLACKWARE",
"url" : "http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683"
},
{
"name" : "102972",
"refsource" : "SUNALERT",
"url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1"
},
{
"name" : "SUSE-SA:2006:001",
"refsource" : "SUSE",
"url" : "http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html"
},
{
"name" : "SUSE-SR:2006:002",
"refsource" : "SUSE",
"url" : "http://www.novell.com/linux/security/advisories/2006_02_sr.html"
},
{
"name" : "SUSE-SR:2005:029",
"refsource" : "SUSE",
"url" : "http://www.novell.com/linux/security/advisories/2005_29_sr.html"
},
{
"name" : "TSLSA-2005-0072",
"refsource" : "TRUSTIX",
"url" : "http://www.trustix.org/errata/2005/0072/"
},
{
"name" : "USN-227-1",
"refsource" : "UBUNTU",
"url" : "http://www.ubuntulinux.org/usn/usn-227-1"
},
{
"name" : "15726",
"refsource" : "BID",
"url" : "http://www.securityfocus.com/bid/15726"
},
{
"name" : "15727",
"refsource" : "BID",
"url" : "http://www.securityfocus.com/bid/15727"
},
{
"name" : "oval:org.mitre.oval:def:9760",
"refsource" : "OVAL",
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9760"
},
{
"name" : "ADV-2005-2786",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2005/2786"
},
{
"name" : "ADV-2005-2789",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2005/2789"
},
{
"name" : "ADV-2005-2790",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2005/2790"
},
{
"name" : "ADV-2005-2788",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2005/2788"
},
{
"name" : "ADV-2005-2856",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2005/2856"
},
{
"name" : "ADV-2005-2787",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2005/2787"
},
{
"name" : "ADV-2007-2280",
"refsource" : "VUPEN",
"url" : "http://www.vupen.com/english/advisories/2007/2280"
},
{
"name" : "1015309",
"refsource" : "SECTRACK",
"url" : "http://securitytracker.com/id?1015309"
},
{
"name" : "1015324",
"refsource" : "SECTRACK",
"url" : "http://securitytracker.com/id?1015324"
},
{
"name" : "17908",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17908"
},
{
"name" : "17912",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17912"
},
{
"name" : "17916",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17916"
},
{
"name" : "17920",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17920"
},
{
"name" : "17921",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17921"
},
{
"name" : "17929",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17929"
},
{
"name" : "17940",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17940"
},
{
"name" : "17976",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17976"
},
{
"name" : "18009",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18009"
},
{
"name" : "18055",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18055"
},
{
"name" : "18061",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18061"
},
{
"name" : "17897",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17897"
},
{
"name" : "17926",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17926"
},
{
"name" : "18191",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18191"
},
{
"name" : "18192",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18192"
},
{
"name" : "18189",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18189"
},
{
"name" : "18313",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18313"
},
{
"name" : "18336",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18336"
},
{
"name" : "18387",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18387"
},
{
"name" : "18416",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18416"
},
{
"name" : "18349",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18349"
},
{
"name" : "18385",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18385"
},
{
"name" : "18389",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18389"
},
{
"name" : "18448",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18448"
},
{
"name" : "18398",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18398"
},
{
"name" : "18407",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18407"
},
{
"name" : "18534",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18534"
},
{
"name" : "18549",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18549"
},
{
"name" : "18582",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18582"
},
{
"name" : "18303",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18303"
},
{
"name" : "18517",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18517"
},
{
"name" : "18554",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18554"
},
{
"name" : "17955",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/17955"
},
{
"name" : "18674",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18674"
},
{
"name" : "18675",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18675"
},
{
"name" : "18679",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18679"
},
{
"name" : "18908",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18908"
},
{
"name" : "18913",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18913"
},
{
"name" : "19230",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/19230"
},
{
"name" : "19377",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/19377"
},
{
"name" : "18503",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18503"
},
{
"name" : "18147",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18147"
},
{
"name" : "18380",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18380"
},
{
"name" : "18428",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18428"
},
{
"name" : "18436",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/18436"
},
{
"name" : "19797",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/19797"
},
{
"name" : "19798",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/19798"
},
{
"name" : "25729",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/25729"
},
{
"name" : "26413",
"refsource" : "SECUNIA",
"url" : "http://secunia.com/advisories/26413"
},
{
"name" : "233",
"refsource" : "SREASON",
"url" : "http://securityreason.com/securityalert/233"
},
{
"name" : "234",
"refsource" : "SREASON",
"url" : "http://securityreason.com/securityalert/234"
},
{
"name" : "xpdf-dctstream-baseline-bo(23444)",
"refsource" : "XF",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23444"
},
{
"name" : "xpdf-dctstream-progressive-bo(23443)",
"refsource" : "XF",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23443"
}
]
}
}