CVE-2006-0301
EPSS 3.1%libextractor - several
Published: 1/30/2006Modified: 4/28/2026
Description
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Affected packages (7)
- Debian/gpdffrom 0, < 2.8.2-1.2sarge3
- Debian/libextractorfrom 0, < 0.5.10-1
- Debian/libextractorfrom 0, < 0.4.2-2sarge3
- Debian/pdfkit.frameworkfrom 0, < 0.8-2sarge2
- Debian/popplerfrom 0, < 0.4.5-1
- Debian/xpdffrom 0, < 3.01-6
- Debian/xpdffrom 0, < 3.00-13.5