CVE-2007-0104
published 2007-01-09CVE-2007-0104: The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
6.03%
92.5th percentile
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.4.5-5.1 (bookworm) | poppler 0.4.5-5.1 (bookworm) |
| debian | xpdf | < poppler 0.4.5-5.1 (bookworm) | poppler 0.4.5-5.1 (bookworm) |
| freedesktop | poppler | >= 0 < 0.4.5-5.1 | 0.4.5-5.1 |
| freedesktop | poppler | >= 0 < 0.4.5-5.1 | 0.4.5-5.1 |
| freedesktop | poppler | >= 0 < 0.4.5-5.1 | 0.4.5-5.1 |
| freedesktop | poppler | >= 0 < 0.4.5-5.1 | 0.4.5-5.1 |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| kde | kde | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 3.02 | 3.02 |
| xpdf | xpdf | >= 0 < 3.02 | 3.02 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
teTeX vulnerability
vendor_ubuntu·2007-01-26
CVE-2007-0104 teTeX vulnerability
Title: teTeX vulnerability
Summary: teTeX vulnerability
USN-410-1 fixed vulnerabilities in the poppler PDF loader library. This
update provides the corresponding updates for a copy of this code in
tetex-bin in Ubuntu 5.10. Versions of tetex-bin after Ubuntu 5.10 use
poppler directly and do not need a separate update.
Original advisory details:
The poppler PDF loader library did not limit the recursion depth of
the page model tree. By tricking a user into opening a specially
crafter PDF file, this could be exploited to trigger an infinite loop
and eventually crash an application that uses this library.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
poppler vulnerability
vendor_ubuntu·2007-01-19
CVE-2007-0104 poppler vulnerability
Title: poppler vulnerability
Summary: poppler vulnerability
The poppler PDF loader library did not limit the recursion depth of
the page model tree. By tricking a user into opening a specially
crafter PDF file, this could be exploited to trigger an infinite loop
and eventually crash an application that uses this library.
kpdf in Ubuntu 5.10, and KOffice in all Ubuntu releases contains a
copy of this code and thus is affected as well.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2007-0104: poppler - The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) k...
vendor_debian·2007·CVSS 6.8
CVE-2007-0104 [MEDIUM] CVE-2007-0104: poppler - The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) k...
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
Scope: local
bookworm: resolved (fixed in 0.4.5-5.1)
bullseye: resolved (fixed in 0.4.5-5.1)
forky: resolved (fixed in 0.4.5-5.1)
sid: resolved (fixed in 0.4.5-5.1)
trixie: resolved (fixed in 0.4.5-5.1)
Red Hat
xpdf infinite loop DoS
vendor_redhat·CVSS 6.8
CVE-2007-0104 [MEDIUM] xpdf infinite loop DoS
xpdf infinite loop DoS
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
Statement: Not Vulnerable. This flaw is the result of an infinite recursion flaw in xpdf, which cannot result in arbitrary code execution.
GHSA
GHSA-8w95-hg52-rgm5: The Adobe PDF specification 1
ghsa_unreviewed·2022-05-01
CVE-2007-0104 [MEDIUM] CWE-20 GHSA-8w95-hg52-rgm5: The Adobe PDF specification 1
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
OSV
CVE-2007-0104: The Adobe PDF specification 1
osv·2007-01-09·CVSS 6.8
CVE-2007-0104 [MEDIUM] CVE-2007-0104: The Adobe PDF specification 1
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
No detection rules found.
No public exploits indexed.
http://docs.info.apple.com/article.html?artnum=305214http://projects.info-pull.com/moab/MOAB-06-01-2007.htmlhttp://secunia.com/advisories/23791http://secunia.com/advisories/23799http://secunia.com/advisories/23808http://secunia.com/advisories/23813http://secunia.com/advisories/23815http://secunia.com/advisories/23839http://secunia.com/advisories/23844http://secunia.com/advisories/23876http://secunia.com/advisories/24204http://secunia.com/advisories/24479http://securitytracker.com/id?1017514http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.htmlhttp://www.kde.org/info/security/advisory-20070115-1.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2007:018http://www.mandriva.com/security/advisories?name=MDKSA-2007:019http://www.mandriva.com/security/advisories?name=MDKSA-2007:020http://www.mandriva.com/security/advisories?name=MDKSA-2007:021http://www.mandriva.com/security/advisories?name=MDKSA-2007:022http://www.mandriva.com/security/advisories?name=MDKSA-2007:024http://www.novell.com/linux/security/advisories/2007_3_sr.htmlhttp://www.securityfocus.com/archive/1/457055/100/0/threadedhttp://www.securityfocus.com/bid/21910http://www.securitytracker.com/id?1017749http://www.ubuntu.com/usn/usn-410-1http://www.ubuntu.com/usn/usn-410-2http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2007/0203http://www.vupen.com/english/advisories/2007/0212http://www.vupen.com/english/advisories/2007/0244http://www.vupen.com/english/advisories/2007/0930https://exchange.xforce.ibmcloud.com/vulnerabilities/31364https://issues.rpath.com/browse/RPL-964http://docs.info.apple.com/article.html?artnum=305214http://projects.info-pull.com/moab/MOAB-06-01-2007.htmlhttp://secunia.com/advisories/23791http://secunia.com/advisories/23799http://secunia.com/advisories/23808http://secunia.com/advisories/23813http://secunia.com/advisories/23815http://secunia.com/advisories/23839http://secunia.com/advisories/23844http://secunia.com/advisories/23876http://secunia.com/advisories/24204http://secunia.com/advisories/24479http://securitytracker.com/id?1017514http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.htmlhttp://www.kde.org/info/security/advisory-20070115-1.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2007:018http://www.mandriva.com/security/advisories?name=MDKSA-2007:019http://www.mandriva.com/security/advisories?name=MDKSA-2007:020http://www.mandriva.com/security/advisories?name=MDKSA-2007:021http://www.mandriva.com/security/advisories?name=MDKSA-2007:022http://www.mandriva.com/security/advisories?name=MDKSA-2007:024http://www.novell.com/linux/security/advisories/2007_3_sr.htmlhttp://www.securityfocus.com/archive/1/457055/100/0/threadedhttp://www.securityfocus.com/bid/21910http://www.securitytracker.com/id?1017749http://www.ubuntu.com/usn/usn-410-1http://www.ubuntu.com/usn/usn-410-2http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2007/0203http://www.vupen.com/english/advisories/2007/0212http://www.vupen.com/english/advisories/2007/0244http://www.vupen.com/english/advisories/2007/0930https://exchange.xforce.ibmcloud.com/vulnerabilities/31364https://issues.rpath.com/browse/RPL-964
2007-01-09
Published