Back to Database
Status published
High
CVE-2005-0064
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf...
Vulnerability Description
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-0064
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/17277
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11781
- http://www.redhat.com/support/errata/RHSA-2005-066.html
- http://www.redhat.com/support/errata/RHSA-2005-034.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:018
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:017
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:016
- http://www.trustix.org/errata/2005/0003/
- https://bugzilla.fedora.us/show_bug.cgi?id=2352
- https://bugzilla.fedora.us/show_bug.cgi?id=2353
- http://www.debian.org/security/2005/dsa-645
- https://security.gentoo.org/glsa/200502-10
- http://www.redhat.com/support/errata/RHSA-2005-026.html
- http://www.redhat.com/support/errata/RHSA-2005-053.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:020
- https://security.gentoo.org/glsa/200501-28
- http://www.idefense.com/application/poi/display?id=186&type=vulnerabilities
- http://www.redhat.com/support/errata/RHSA-2005-059.html
- http://marc.info/?l=bugtraq&m=110625368019554&w=2
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt
- http://www.debian.org/security/2005/dsa-648
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:021
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000921
- ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:019
- http://www.redhat.com/support/errata/RHSA-2005-057.html
More from xpdf
View All →CVE-2010-0206
xpdf allows remote attackers to cause a denial of service...
Medium
5.5
CVE-2007-5393
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in...
Critical
9.3
CVE-2007-5392
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf...
Critical
9.3
CVE-2007-4352
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in...
High
7.6
CVE-2007-0104
The Adobe PDF specification 1.3, as implemented by (a) xpdf...
Medium
6.8
Affected Vendor
xpdf
View all reports →Affected Software
xpdf
Vulnerable Versions:
0.2, 0.3, 0.4, 0.5, 0.5a, 0.6, 0.7, 0.7a, 0.80, 0.90, 0.91, 0.91a, 0.91b, 0.91c, 0.92, 0.92a, 0.92b, 0.92c, 0.92d, 0.92e, 0.93, 0.93a, 0.93b, 0.93c, 1.0, 1.0a, 1.1, 2.0, 2.1, 2.2, 2.3, 3.0
Timeline
Official Publish:
January 19th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.