FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2097

This CVE name corresponds to:

Entered Topic
2005-08-12 xpdf -- disk fill DoS vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2097
Phase Assigned(20050630)

Description

xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.

References

Source Reference
DEBIAN DSA-780
DEBIAN DSA-936
DEBIAN DSA-1136
FEDORA FLSA:175404
FEDORA FLSA-2006:176751
MANDRIVA MDKSA-2005:138
REDHAT RHSA-2005:670
REDHAT RHSA-2005:671
REDHAT RHSA-2005:706
REDHAT RHSA-2005:708
SCO SCOSA-2005.42
SUNALERT 102972
SUSE SUSE-SR:2005:019
UBUNTU USN-163-1
BID 14529
OVAL oval:org.mitre.oval:def:10280
VUPEN ADV-2007-2280
SECUNIA 17277
SECUNIA 18398
SECUNIA 18407
SECUNIA 21339
SECUNIA 25729