PT-2007-7530 · Gnu+6 · Libextractor+14

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-4352

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kdegraphics3-pdf versions (affected versions not specified) tetex-latex-3.0 version (affected versions not specified) tetex-xdvi-3.0 version (affected versions not specified) tetex-dvips-3.0 version (affected versions not specified) tetex-doc-3.0 version (affected versions not specified) tetex-3.0 version (affected versions not specified) libextractor versions (affected versions not specified) libextractor-devel versions (affected versions not specified) Xpdf version 3.02pl1 tetex-fonts-3.0 version (affected versions not specified) tetex-afm-3.0 version (affected versions not specified)
Description The issue involves multiple vulnerabilities in various packages of SUSE Linux Enterprise and Red Hat Enterprise Linux operating systems, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, an array index error in the DCTStream::readProgressiveDataUnit method in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Recommendations As a temporary workaround, consider disabling the DCTStream::readProgressiveDataUnit method in Xpdf until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the affected packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04628
BDU:2015-04629
BDU:2015-04630
BDU:2015-06556
BDU:2015-06557
BDU:2015-06558
BDU:2015-06559
BDU:2015-06560
BDU:2015-06561
BDU:2015-06562
CVE-2007-4352
DSA-1480-1
DSA-1509-1
DSA-1537-1
DTSA-85-1
DTSA-86-1
OPENSUSE-SU-2024:10707-1
OPENSUSE-SU-2024:11181-1
RHSA-2007:1021
RHSA-2007:1022
RHSA-2007:1024
RHSA-2007:1025
RHSA-2007:1026
RHSA-2007:1027
RHSA-2007:1029
RHSA-2007:1030
RHSA-2007_1021
RHSA-2007_1022
RHSA-2007_1024
RHSA-2007_1025
RHSA-2007_1026
RHSA-2007_1027
RHSA-2007_1029

Affected Products

Cups
Office
Red Hat
Xpdf
Kdegraphics3-Pdf
Libextractor
Libextractor-Devel
Poppler
Tetex-3.0
Tetex-Afm-3.0
Tetex-Doc-3.0
Tetex-Dvips-3.0
Tetex-Fonts-3.0
Tetex-Latex-3.0
Tetex-Xdvi-3.0