PT-2007-7531 · Gnu+5 · Libextractor+12

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2007-5392

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdegraphics3-pdf versions (affected versions not specified) tetex-latex-3.0 versions (affected versions not specified) tetex-xdvi-3.0 versions (affected versions not specified) tetex-dvips-3.0 versions (affected versions not specified) tetex-doc-3.0 versions (affected versions not specified) tetex-3.0 versions (affected versions not specified) libextractor versions (affected versions not specified) libextractor-devel versions (affected versions not specified) tetex-fonts-3.0 versions (affected versions not specified) tetex-afm-3.0 versions (affected versions not specified) Xpdf version 3.02p11
Description The issue involves multiple vulnerabilities in various packages of SUSE Linux Enterprise and Red Hat Enterprise Linux operating systems, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, an integer overflow in the DCTStream::reset method in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Recommendations As a temporary workaround, consider disabling the DCTStream::reset method in Xpdf until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04628
BDU:2015-04629
BDU:2015-04630
BDU:2015-06556
BDU:2015-06557
BDU:2015-06558
BDU:2015-06559
BDU:2015-06560
BDU:2015-06561
BDU:2015-06562
CVE-2007-5392
DSA-1480-1
DSA-1509-1
DSA-1537-1
DTSA-85-1
DTSA-86-1
OPENSUSE-SU-2024:11181-1
RHSA-2007:1021
RHSA-2007:1022
RHSA-2007:1024
RHSA-2007:1025
RHSA-2007:1026
RHSA-2007:1027
RHSA-2007:1029
RHSA-2007:1030
RHSA-2007_1021
RHSA-2007_1022
RHSA-2007_1024
RHSA-2007_1025
RHSA-2007_1026
RHSA-2007_1027
RHSA-2007_1029

Produtos afetados

Red Hat
Suse Linux Enterprise
Xpdf
Kdegraphics3-Pdf
Libextractor
Libextractor-Devel
Tetex-3.0
Tetex-Afm-3.0
Tetex-Doc-3.0
Tetex-Dvips-3.0
Tetex-Fonts-3.0
Tetex-Latex-3.0
Tetex-Xdvi-3.0