CVE-2005-3625

CRITICAL

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end premature...

Affects 33 products across 18 vendors.

BCS7.87
CVSS 2.010.0
EPSS3.9%
Percentile89th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-399: Resource Management Errors

Broad class covering failures in managing system resources such as memory, file handles, and connections.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2005. A critical vulnerability affects Conectiva systems (CVE-2005-3625). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2005-GLOBAL-002759-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2005-3625?
This vulnerability was disclosed in 2005. A critical vulnerability affects Conectiva systems (CVE-2005-3625). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2005-3625?
CVE-2005-3625 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.9%.
Is CVE-2005-3625 actively exploited?
No confirmed active exploitation of CVE-2005-3625 as of 2026-05-30.
How do I remediate CVE-2005-3625?
Priority: MEDIUM. Advisory: http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html PSIRT: [email protected]
What systems are affected by CVE-2005-3625?
CVE-2005-3625 affects: Conectiva, Debian, Easy Software Products, Gentoo, Kde, Kde, Kde, Kde.
Vulnerability Details
CVE IDCVE-2005-3625
BSIDBS-2005-GLOBAL-002759-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2005-12-31
Last Modified2026-04-16
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Conectiva Linux
Debian Debian Linux
Easy Software Products Cups
Gentoo Linux
Kde Kpdf
Kde Kword
Kde Kdegraphics
Kde Koffice
Libextractor Libextractor
Mandrakesoft Mandrake Linux Corporate Server
Mandrakesoft Mandrake Linux
Poppler Poppler
Redhat Enterprise Linux
Redhat Linux Advanced Workstation
Redhat Linux
Redhat Enterprise Linux Desktop
Redhat Fedora Core
Sco Openserver
Sgi Propack
Slackware Slackware Linux
Suse Suse Linux
Tetex Tetex
Trustix Secure Linux
Turbolinux Turbolinux Multimedia
Turbolinux Turbolinux Personal
Turbolinux Turbolinux Desktop
Turbolinux Turbolinux Home
Turbolinux Turbolinux Workstation
Turbolinux Turbolinux
Turbolinux Turbolinux Server
Turbolinux Turbolinux Appliance Server
Ubuntu Ubuntu Linux
Xpdf Xpdf
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 7498 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash2764a3cf1ceed045a2926d3dcf81f3be9a78b2515b45d8e49c268b5957bb5d7cc4599b091df2c2d029b7197788e4cacac28985b1384661c7ff10fb9cd61a6d84
Related CVEs affecting Conectiva
CVE-2004-0557 10.0 Multiple buffer overflows in the st_wavstartread function in wav.c for Sound ... CVE-2000-0747 10.0 The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an i... CVE-2000-0666 10.0 rpc.statd in the nfs-utils package in various Linux distributions does not pr... CVE-2000-0844 10.0 Some functions that implement the locale subsystem on Unix do not properly c... CVE-2004-0904 10.0 Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the P...
View all Conectiva CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →