PT-2007-7510 · Foxtail Technologies+6 · Xpdf+7

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-3387

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xpdf version 3.02 poppler versions prior to 0.5.91 gpdf versions prior to 2.8.2 kpdf (affected versions not specified) kdegraphics (affected versions not specified) CUPS (affected versions not specified) PDFedit (affected versions not specified)
Description The issue is related to an integer overflow in the StreamPredictor::StreamPredictor function, which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function. This could lead to disruption of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerabilities can be carried out remotely.
Recommendations For xpdf version 3.02, update to a version that fixes the integer overflow issue. For poppler versions prior to 0.5.91, update to version 0.5.91 or later. For gpdf versions prior to 2.8.2, update to version 2.8.2 or later. For kpdf, kdegraphics, CUPS, and PDFedit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03565
BDU:2015-03566
BDU:2015-03567
CVE-2007-3387
DSA-1347-1
DSA-1348-1
DSA-1349-1
DSA-1350-1
DSA-1352-1
DSA-1354-1
DSA-1355-1
DSA-1357-1
DTSA-49-1
DTSA-50-1
DTSA-54-1
DTSA-62-1
OPENSUSE-SU-2024:10707-1
RHSA-2007:0720
RHSA-2007:0729
RHSA-2007:0730
RHSA-2007:0731
RHSA-2007:0732
RHSA-2007:0735
RHSA-2007_0720
RHSA-2007_0729
RHSA-2007_0730
RHSA-2007_0731
RHSA-2007_0732
RHSA-2007_0735

Affected Products

Cups
Pdfedit
Red Hat
Gpdf
Kdegraphics
Kpdf
Poppler
Xpdf