PT-2007-1589 · Kde · Kpdf

Published

2007-01-09

·

Updated

2024-06-15

·

CVE-2007-0104

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xpdf versions 3.0.1 patch 2 kpdf in KDE versions prior to 3.5.5 poppler versions prior to 0.5.4
Description The issue allows remote attackers to have an unknown impact, possibly including denial of service, arbitrary code execution, or memory corruption, via a PDF file with a crafted catalog dictionary or a crafted Pages attribute that references an invalid page tree node.
Recommendations For xpdf version 3.0.1 patch 2, update to a version later than 3.0.1 patch 2. For kpdf in KDE versions prior to 3.5.5, update to version 3.5.5 or later. For poppler versions prior to 0.5.4, update to version 0.5.4 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0104
OPENSUSE-SU-2024:10707-1
OPENSUSE-SU-2024:11181-1

Affected Products

Kpdf