security flaw
Published Jan 6, 2006
10.0
HIGHCVSS 2.0
EPSS 3.82%
Description
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Affected products
No data.
Configuration 1
- 1.1.22
- 1.1.22_rc1
- 1.1.23
- 1.1.23_rc1
- 3.2
- 3.4.3
- 1.4
- 1.4.1
- 1.4.2
- 3.2
- 3.4.3
- 1.4.2
- n/a
- 0.4.2
- 3.0
- 1.0.7
- 2.0
- 2.0.1
- 2.0.2
- 3.0
- 3.0
- 10.0
Configuration 2
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- n/a
- 10.1
- 10.1
- 10.2
- 10.2
- 2006
- 2006
- 2.1
- 2.1
- 3.0
- 3.0
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 3.0
- 3.0
- 3.0
- 4.0
- 4.0
- 4.0
- 3.0
- 4.0
- core_1.0
- core_2.0
- core_3.0
- core_4.0
- 7.3
- 9.0
- 2.1
- 2.1
- 5.0.7
- 6.0
- 9.0
- 9.1
- 10.0
- 10.1
- 10.2
- 1.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.1
- 9.1
- 9.1
- 9.2
- 9.2
- 9.2
- 9.3
- 9.3
- 9.3
- 10.0
- 10.0
- 2.0
- 2.2
- 3.0
- 10
- fuji
- 1.0_hosting_edition
- 1.0_workgroup_edition
- 10.0
- n/a
- n/a
- n/a
- 8.0
- 10.0
- 10.0_x86
- 8.0
- 4.1
- 4.1
- 5.04
- 5.04
- 5.04
- 5.10
- 5.10
- 5.10
No data.
Red Hat Enterprise Linux 3
cups-1:1.1.17-13.3.36
Fixed · RHSA-2006:0163
Red Hat Enterprise Linux 3
tetex-0:1.0.7-67.9
Fixed · RHSA-2006:0160
Red Hat Enterprise Linux 3
xpdf-1:2.02-9.8
Fixed · RHSA-2005:840
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.10
Fixed · RHSA-2006:0163
Red Hat Enterprise Linux 4
gpdf-0:2.8.2-7.4
Fixed · RHSA-2006:0177
Red Hat Enterprise Linux 4
kdegraphics-7:3.3.1-3.6
Fixed · RHSA-2005:868
Red Hat Enterprise Linux 4
tetex-0:2.0.2-22.EL4.7
Fixed · RHSA-2006:0160
Red Hat Enterprise Linux 4
xpdf-1:3.00-11.10
Fixed · RHSA-2005:840
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | cups-1:1.1.17-13.3.36 | Fixed | RHSA-2006:0163 |
| Red Hat Enterprise Linux 3 | tetex-0:1.0.7-67.9 | Fixed | RHSA-2006:0160 |
| Red Hat Enterprise Linux 3 | xpdf-1:2.02-9.8 | Fixed | RHSA-2005:840 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.10 | Fixed | RHSA-2006:0163 |
| Red Hat Enterprise Linux 4 | gpdf-0:2.8.2-7.4 | Fixed | RHSA-2006:0177 |
| Red Hat Enterprise Linux 4 | kdegraphics-7:3.3.1-3.6 | Fixed | RHSA-2005:868 |
| Red Hat Enterprise Linux 4 | tetex-0:2.0.2-22.EL4.7 | Fixed | RHSA-2006:0160 |
| Red Hat Enterprise Linux 4 | xpdf-1:3.00-11.10 | Fixed | RHSA-2005:840 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.82% (0.03823) | 89.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.77% (0.03765) | 88.47th | v5 (v2026.06.15) |
| Mar 17, 2025 | 11.29% (0.11286) | 92.99th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.61% (0.00606) | 79.28th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.61% (0.00606) | 77.90th | v3 (v2023.03.01) |
| Jun 1, 2023 | 0.61% (0.00606) | 75.50th | v3 (v2023.03.01) |
| Apr 12, 2023 | 0.62% (0.00623) | 75.77th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.43% (0.00425) | 70.31th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.35% (0.03345) | 84.35th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.35% (0.03345) | 82.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.35% (0.03345) | 65.84th | v2 (v2022.01.01) |
References (89)
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt vendor-advisoryx_refsource_SCO
- ftp://patches.sgi.com/support/free/security/advisories/20051201-01-U vendor-advisoryx_refsource_SGI
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U vendor-advisoryx_refsource_SGI
- ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U vendor-advisoryx_refsource_SGI
- http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html vendor-advisoryx_refsource_SUSEPatch
- http://rhn.redhat.com/errata/RHSA-2006-0177.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://scary.beasts.org/security/CESA-2005-003.txt x_refsource_MISCExploit
- http://secunia.com/advisories/18147 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18303 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18312 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18313 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18329 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18332 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18334 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18335 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18338 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18349 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18373 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18375 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18380 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18385 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18387 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18389 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18398 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18407 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18414 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18416 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18423 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18425 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18428 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18436 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18448 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18463 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18517 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18534 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18554 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18582 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18642 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18644 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18674 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18675 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18679 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18908 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18913 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19230 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19377 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25729 third-party-advisoryx_refsource_SECUNIA
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683 vendor-advisoryx_refsource_SLACKWARE
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1 vendor-advisoryx_refsource_SUNALERT
- http://www.debian.org/security/2005/dsa-931 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-932 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-937 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-938 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-940 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-936 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-950 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-961 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-962 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200601-02.xml vendor-advisoryx_refsource_GENTOOPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200601-17.xml vendor-advisoryx_refsource_GENTOO
- http://www.kde.org/info/security/advisory-20051207-2.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:003 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:004 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:005 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:006 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:008 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:010 vendor-advisoryx_refsource_MANDRAKE
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:011 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:012 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00010.html x_refsource_CONFIRMPatch
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00011.html x_refsource_CONFIRMPatch
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00030.html vendor-advisoryx_refsource_FEDORA
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00031.html vendor-advisoryx_refsource_FEDORA
- http://www.redhat.com/support/errata/RHSA-2006-0160.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0163.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/427053/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/archive/1/427990/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/16143 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2006/0002/ vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/0047 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2280 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-3625 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617827 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24023 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2005-3625
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9575 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/236-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2005-3625
Change history (0)
No recorded changes yet.