CVE-2005-3624

Easy Software Products Cups - Numeric Error

Title source: rule

Description

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.

Scores

EPSS 0.0736
EPSS Percentile 91.6%

Classification

CWE
CWE-189
Status draft

Affected Products (50)

easy_software_products/cups
easy_software_products/cups
easy_software_products/cups
easy_software_products/cups
kde/kdegraphics
kde/kdegraphics
kde/koffice
kde/koffice
kde/koffice
kde/kpdf
kde/kpdf
kde/kword
libextractor/libextractor
poppler/poppler
sgi/propack
... and 35 more

Timeline

Published Dec 31, 2005
Tracked Since Feb 18, 2026