ubuntu · CVE-2005-2097

Quick triage

Priority: low Published: 2005-08-16 00:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2005-2097 low priority: Ubuntu including 6 source packages (cups, cupsys, gpdf, kdegraphics, poppler, xpdf), 54 status rows across 9 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): released 22, DNE 14, not-affected 11, needs-triage 6, ignored 1.

Description:

xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.

cvelogic Threat Intelligence