CVE-2005-2097

xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kde:kpdf:*:*:*:*:*:*:*:*
cpe:2.3:a:xpdf:xpdf:3.0:*:*:*:*:*:*:*
cpe:2.3:a:xpdf:xpdf:3.0_pl2:*:*:*:*:*:*:*
cpe:2.3:a:xpdf:xpdf:3.0_pl3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-08-16 04:00

Updated : 2023-12-10 10:28


NVD link : CVE-2005-2097

Mitre link : CVE-2005-2097

CVE.ORG link : CVE-2005-2097


JSON object : View

Products Affected

kde

  • kpdf

xpdf

  • xpdf