CVE-2004-0889

Published Jan 27, 2005

Last updated 10 days ago

Overview

Description
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
Source
cve@mitre.org
NVD status
Modified
Products
cups, gpdf, koffice, kpdf, pdftohtml, tetex, xpdf, debian_linux, linux, kde, enterprise_linux, enterprise_linux_desktop, fedora_core, linux_advanced_workstation, suse_linux, ubuntu_linux

Risk scores

CVSS 2.0

Type
Primary
Base score
10
Impact score
10
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations