xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-08-15 21:00
Updated : 2018-10-19 08:32
NVD link : CVE-2005-2097
Mitre link : CVE-2005-2097
JSON object : View
CWE
Products Affected
kde
- kpdf
xpdf
- xpdf