security flaw
Published Jan 6, 2006
7.5
HIGHCVSS 2.0
EPSS 5.52%
Description
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
cups-1:1.1.17-13.3.36
Fixed · RHSA-2006:0163
Red Hat Enterprise Linux 3
tetex-0:1.0.7-67.9
Fixed · RHSA-2006:0160
Red Hat Enterprise Linux 3
xpdf-1:2.02-9.8
Fixed · RHSA-2005:840
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.10
Fixed · RHSA-2006:0163
Red Hat Enterprise Linux 4
gpdf-0:2.8.2-7.4
Fixed · RHSA-2006:0177
Red Hat Enterprise Linux 4
kdegraphics-7:3.3.1-3.6
Fixed · RHSA-2005:868
Red Hat Enterprise Linux 4
tetex-0:2.0.2-22.EL4.7
Fixed · RHSA-2006:0160
Red Hat Enterprise Linux 4
xpdf-1:3.00-11.10
Fixed · RHSA-2005:840
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | cups-1:1.1.17-13.3.36 | Fixed | RHSA-2006:0163 |
| Red Hat Enterprise Linux 3 | tetex-0:1.0.7-67.9 | Fixed | RHSA-2006:0160 |
| Red Hat Enterprise Linux 3 | xpdf-1:2.02-9.8 | Fixed | RHSA-2005:840 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.10 | Fixed | RHSA-2006:0163 |
| Red Hat Enterprise Linux 4 | gpdf-0:2.8.2-7.4 | Fixed | RHSA-2006:0177 |
| Red Hat Enterprise Linux 4 | kdegraphics-7:3.3.1-3.6 | Fixed | RHSA-2005:868 |
| Red Hat Enterprise Linux 4 | tetex-0:2.0.2-22.EL4.7 | Fixed | RHSA-2006:0160 |
| Red Hat Enterprise Linux 4 | xpdf-1:3.00-11.10 | Fixed | RHSA-2005:840 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.52% (0.05521) | 92.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.44% (0.05439) | 91.67th | v5 (v2026.06.15) |
| Mar 30, 2025 | 4.33% (0.04327) | 87.84th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.38% (0.08380) | 86.92th | v4 (v2025.03.14) |
| Mar 19, 2025 | 4.33% (0.04327) | 87.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.56% (0.02564) | 84.50th | v4 (v2025.03.14) |
| Dec 17, 2024 | 6.69% (0.06690) | 93.75th | v3 (v2023.03.01) |
| Apr 12, 2023 | 3.64% (0.03642) | 90.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.60% (0.02602) | 88.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.63% (0.05630) | 90.10th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.63% (0.05630) | 89.12th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.63% (0.05630) | 76.75th | v2 (v2022.01.01) |
References (90)
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt vendor-advisoryx_refsource_SCO
- ftp://patches.sgi.com/support/free/security/advisories/20051201-01-U vendor-advisoryx_refsource_SGI
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U vendor-advisoryx_refsource_SGI
- ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U vendor-advisoryx_refsource_SGI
- http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html vendor-advisoryx_refsource_SUSEPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0177.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://scary.beasts.org/security/CESA-2005-003.txt x_refsource_MISCExploitVendor Advisory
- http://secunia.com/advisories/18147 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18303 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18312 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18313 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18329 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18332 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18334 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18335 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18338 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18349 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18373 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18375 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18380 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18385 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18387 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18389 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18398 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18407 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18414 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18416 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18423 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18425 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18428 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18436 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18448 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18463 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18517 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18534 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18554 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18582 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18642 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18644 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18674 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18675 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18679 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18908 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18913 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19230 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19377 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25729 third-party-advisoryx_refsource_SECUNIA
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.472683 vendor-advisoryx_refsource_SLACKWARE
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.474747 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1 vendor-advisoryx_refsource_SUNALERT
- http://www.debian.org/security/2005/dsa-931 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-932 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-937 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-938 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2005/dsa-940 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-936 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-950 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-961 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2006/dsa-962 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200601-02.xml vendor-advisoryx_refsource_GENTOOPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200601-17.xml vendor-advisoryx_refsource_GENTOO
- http://www.kde.org/info/security/advisory-20051207-2.txt x_refsource_CONFIRMPatch
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:003 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:004 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:005 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:006 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:008 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:010 vendor-advisoryx_refsource_MANDRAKE
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:011 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:012 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00010.html x_refsource_CONFIRMPatch
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00011.html x_refsource_CONFIRMPatch
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00030.html vendor-advisoryx_refsource_FEDORA
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00031.html vendor-advisoryx_refsource_FEDORA
- http://www.redhat.com/support/errata/RHSA-2006-0160.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0163.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/427053/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/archive/1/427990/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/16143 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2006/0002/ vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/0047 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2280 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-3627 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617829 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24024 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24025 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2005-3627
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10200 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/236-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2005-3627
Change history (0)
No recorded changes yet.