PT-2007-7532 · Gnu+4 · Libextractor+11

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2007-5393

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdegraphics3-pdf versions (affected versions not specified) tetex-latex-3.0 version 3.0 tetex-xdvi-3.0 version 3.0 tetex-dvips-3.0 version 3.0 tetex-doc-3.0 version 3.0 tetex-3.0 version 3.0 libextractor versions (affected versions not specified) libextractor-devel versions (affected versions not specified) tetex-fonts-3.0 version 3.0 tetex-afm-3.0 version 3.0 Xpdf version 3.02p11
Description The issue involves multiple vulnerabilities in various packages of operating systems, including SUSE Linux Enterprise and Red Hat Enterprise Linux. These vulnerabilities can lead to the disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. Specifically, a heap-based buffer overflow in the CCITTFaxStream::lookChar method in Xpdf's Stream.cc allows remote attackers to execute arbitrary code via a crafted PDF file containing a CCITTFaxDecode filter.
Recommendations For kdegraphics3-pdf, update to a version that contains a fix for this issue. For tetex-latex-3.0, tetex-xdvi-3.0, tetex-dvips-3.0, tetex-doc-3.0, tetex-3.0, tetex-fonts-3.0, and tetex-afm-3.0, update to a version that contains a fix for this issue. For libextractor and libextractor-devel, update to a version that contains a fix for this issue. For Xpdf version 3.02p11, consider disabling the CCITTFaxStream::lookChar method until a patch is available. As a temporary workaround, restrict access to vulnerable packages to minimize the risk of exploitation.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04628
BDU:2015-04629
BDU:2015-04630
BDU:2015-06556
BDU:2015-06557
BDU:2015-06558
BDU:2015-06559
BDU:2015-06560
BDU:2015-06561
BDU:2015-06562
CVE-2007-5393
DSA-1408-1
DSA-1480-1
DSA-1509-1
DSA-1537-1
DTSA-85-1
DTSA-86-1
OPENSUSE-SU-2024:10707-1
OPENSUSE-SU-2024:11181-1
RHSA-2007:1021
RHSA-2007:1022
RHSA-2007:1023
RHSA-2007:1024
RHSA-2007:1025
RHSA-2007:1026
RHSA-2007:1027
RHSA-2007:1028
RHSA-2007:1029
RHSA-2007:1030
RHSA-2007:1031
RHSA-2007:1051
RHSA-2007_1021
RHSA-2007_1022
RHSA-2007_1024
RHSA-2007_1025
RHSA-2007_1026
RHSA-2007_1027
RHSA-2007_1029
RHSA-2007_1051

Produtos afetados

Red Hat
Xpdf
Kdegraphics3-Pdf
Libextractor
Libextractor-Devel
Tetex-3.0
Tetex-Afm-3.0
Tetex-Doc-3.0
Tetex-Dvips-3.0
Tetex-Fonts-3.0
Tetex-Latex-3.0
Tetex-Xdvi-3.0