CVE-2006-1244

gpdf - Unspecified Vulnerability

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.

References (17)

Core 17
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19644
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-979
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-998
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19164
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19364
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-983
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-982
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19091
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19065
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23834
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1019
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16748
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18948
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-984
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19021
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/270-1/

Scores

EPSS 0.0347
EPSS Percentile 87.7%

Details

Status published
Products (27)
debian/debian_linux 3.1 (13 CPE variants)
gnome/gpdf 2.8.2
libextractor/libextractor 0.3.6
libextractor/libextractor 0.3.7
libextractor/libextractor 0.3.8
libextractor/libextractor 0.3.9
libextractor/libextractor 0.3.11
libextractor/libextractor 0.4
libextractor/libextractor 0.4.1
libextractor/libextractor 0.4.2
... and 17 more
Published Mar 15, 2006
Tracked Since Feb 18, 2026