CVE-2004-1125
cupsys - buffer overflow
EPSS 6.6%
描述
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
如何修補 CVE-2004-1125
要修補 CVE-2004-1125,請將受影響套件升級到下列已修補版本。
- Debian/cups—升級至 1.1.22-2 或更新版本
- Debian/cupsys—升級至 1.1.14-5woody11 或更新版本
- —升級至 3.00-11 或更新版本
- —升級至 1.00-3.3 或更新版本
CVE-2004-1125 正在被利用嗎?
中等 — EPSS 為 6.6%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 1.1.22-2
- from 0, < 1.1.14-5woody11
- from 0, < 3.00-11
- from 0, < 1.00-3.3