CVE-2005-3628
EPSS 2.7%
Description
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
How to fix CVE-2005-3628
To remediate CVE-2005-3628, upgrade the affected package to a fixed version below.
- Debian/cups—upgrade to 1.1.22-7 or later
- Debian/libextractor—upgrade to 0.5.9-1 or later
- Debian/xpdf—upgrade to 3.01-4 or later
Is CVE-2005-3628 being exploited?
Low — EPSS is 2.7%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.1.22-7
- from 0, < 0.5.9-1
- from 0, < 3.01-4