CVE-2005-2097
gpdf - multiple vulnerabilities
EPSS 0.43%
描述
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
如何修補 CVE-2005-2097
要修補 CVE-2005-2097,請將受影響套件升級到下列已修補版本。
- Debian/cups—升級至 1.1.22-7 或更新版本
- Debian/gpdf—升級至 2.8.2-1.2sarge5 或更新版本
- Debian/gpdf—升級至 2.8.2-1.2sarge4 或更新版本
- —升級至 2.10.0-1+etch1 或更新版本
- —升級至 4:3.3.2-2sarge1 或更新版本
- —升級至 0.5.8-1 或更新版本
- —升級至 0.4.2-2sarge2 或更新版本
- —升級至 0.4.0-1 或更新版本
- —升級至 3.00-15 或更新版本
- —升級至 3.00-13.6 或更新版本
CVE-2005-2097 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(10)
- from 0, < 1.1.22-7
- from 0, < 2.8.2-1.2sarge5
- from 0, < 2.8.2-1.2sarge4
- from 0, < 2.10.0-1+etch1
- from 0, < 4:3.3.2-2sarge1
- from 0, < 0.5.8-1
- from 0, < 0.4.2-2sarge2
- from 0, < 0.4.0-1
- from 0, < 3.00-15
- from 0, < 3.00-13.6