CVE-2007-3387
published 2007-07-30CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4)…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
8.57%
94.5th percentile
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | <= 1.3.11 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cups | < libextractor 0.5.12-1 (bookworm) | libextractor 0.5.12-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ipe | < libextractor 0.5.12-1 (bookworm) | libextractor 0.5.12-1 (bookworm) |
| debian | libextractor | < libextractor 0.5.12-1 (bookworm) | libextractor 0.5.12-1 (bookworm) |
| debian | poppler | < libextractor 0.5.12-1 (bookworm) | libextractor 0.5.12-1 (bookworm) |
| debian | xpdf | < libextractor 0.5.12-1 (bookworm) | libextractor 0.5.12-1 (bookworm) |
| freedesktop | poppler | < 0.5.91 | 0.5.91 |
| freedesktop | poppler | >= 0 < 0.5.4-6.1 | 0.5.4-6.1 |
| freedesktop | poppler | >= 0 < 0.5.4-6.1 | 0.5.4-6.1 |
| freedesktop | poppler | >= 0 < 0.5.4-6.1 | 0.5.4-6.1 |
| freedesktop | poppler | >= 0 < 0.5.4-6.1 | 0.5.4-6.1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gpdf_project | gpdf | < 2.8.2 | 2.8.2 |
| xpdf | xpdf | >= 0 < 3.02-1.1 | 3.02-1.1 |
| xpdf | xpdf | >= 0 < 3.02-1.1 | 3.02-1.1 |
| xpdf | xpdf | >= 0 < 3.02-1.1 | 3.02-1.1 |
| xpdf | xpdf | >= 0 < 3.02-1.1 | 3.02-1.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
poppler vulnerability
vendor_ubuntu·2007-08-07
CVE-2007-3387 poppler vulnerability
Title: poppler vulnerability
Summary: poppler vulnerability
USN-496-1 fixed a vulnerability in koffice. This update provides the
corresponding updates for poppler, the library used for PDF handling in
Gnome.
Original advisory details:
Derek Noonburg discovered an integer overflow in the Xpdf function
StreamPredictor::StreamPredictor(). By importing a specially crafted PDF
file into KWord, this could be exploited to run arbitrary code with the
user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
koffice vulnerability
vendor_ubuntu·2007-08-03
CVE-2007-3387 koffice vulnerability
Title: koffice vulnerability
Summary: koffice vulnerability
Derek Noonburg discovered an integer overflow in the Xpdf function
StreamPredictor::StreamPredictor(). By importing a specially crafted
PDF file into KWord, this could be exploited to run arbitrary code
with the user's privileges.
Instructions: After a standard system upgrade you need to restart KWord to effect
the necessary changes.
Red Hat
xpdf integer overflow
vendor_redhat·2007-07-28·CVSS 6.8
CVE-2007-3387 [MEDIUM] CWE-190 xpdf integer overflow
xpdf integer overflow
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
Debian
CVE-2007-3387: cups - Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, ...
vendor_debian·2007·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387: cups - Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, ...
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-v25x-frpw-qg4x: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3
ghsa_unreviewed·2022-05-03
CVE-2007-3387 [MEDIUM] CWE-190 GHSA-v25x-frpw-qg4x: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
OSV
CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3
osv·2007-07-30·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
Suricata
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1292 [HIGH] ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids SELECT
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids SELECT"; flow:established,to_server; http.uri; content:"/inlinemod.php?"; nocase; content:"postids="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1292; reference:url,www.milw0rm.com/exploits/3387; classtype:web-application-attack; sid:2004666; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initia
Suricata
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1292 [HIGH] ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids INSERT
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids INSERT"; flow:established,to_server; http.uri; content:"/inlinemod.php?"; nocase; content:"postids="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1292; reference:url,www.milw0rm.com/exploits/3387; classtype:web-application-attack; sid:2004668; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initia
Suricata
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1292 [HIGH] ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids DELETE
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids DELETE"; flow:established,to_server; http.uri; content:"/inlinemod.php?"; nocase; content:"postids="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1292; reference:url,www.milw0rm.com/exploits/3387; classtype:web-application-attack; sid:2004669; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initia
Suricata
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1292 [HIGH] ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids ASCII
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids ASCII"; flow:established,to_server; http.uri; content:"/inlinemod.php?"; nocase; content:"postids="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1292; reference:url,www.milw0rm.com/exploits/3387; classtype:web-application-attack; sid:2004670; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initia
Suricata
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1292 [HIGH] ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UPDATE
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UPDATE"; flow:established,to_server; http.uri; content:"/inlinemod.php?"; nocase; content:"postids="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1292; reference:url,www.milw0rm.com/exploits/3387; classtype:web-application-attack; sid:2004671; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial
Suricata
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1292 [HIGH] ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UNION SELECT
ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Jelsoft vBulletin SQL Injection Attempt -- inlinemod.php postids UNION SELECT"; flow:established,to_server; http.uri; content:"/inlinemod.php?"; nocase; content:"postids="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1292; reference:url,www.milw0rm.com/exploits/3387; classtype:web-application-attack; sid:2004667; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tacti
No public exploits indexed.
Bugzilla
CVE-2007-3387 xpdf integer overflow [F7]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [F7]
CVE-2007-3387 xpdf integer overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
kdegraphics-3.5.7-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3387 xpdf integer overflow [FC6]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [FC6]
CVE-2007-3387 xpdf integer overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2007-3387 xpdf integer overflow [F7]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [F7]
CVE-2007-3387 xpdf integer overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
tetex-3.0-40.1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3387 xpdf integer overflow [F7]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [F7]
CVE-2007-3387 xpdf integer overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
poppler-0.5.4-8.fc7 has been submitted as an update for Fedora 7
---
poppler-0.5.4-8.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
poppler-0.5.4-8.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
poppler-0.5.4-8.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3387 xpdf integer overflow [F7]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [F7]
CVE-2007-3387 xpdf integer overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
cups-1.2.12-4.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3387 xpdf integer overflow [FC6]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [FC6]
CVE-2007-3387 xpdf integer overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Fedora Core 6 reached end of life, so this issue can not be addressed there any
more.
Bugzilla
CVE-2007-3387 xpdf integer overflow [FC6]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [FC6]
CVE-2007-3387 xpdf integer overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Than, you'll have to do this one, I don't have access to Core6. (F-7/ and devel/
branches are done).
---
it's fixed in kdegraphics-3_5_7-1_fc6_1, and will be pushed into FC6-update
today.
Bugzilla
CVE-2007-3387 xpdf integer overflow [FC6]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [FC6]
CVE-2007-3387 xpdf integer overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
FC6 is EOLed now.
Bugzilla
CVE-2007-3387 xpdf integer overflow [F7]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [F7]
CVE-2007-3387 xpdf integer overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
koffice-1.6.3-9.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-3387 xpdf integer overflow [FC6]
bugzilla·2007-08-09·CVSS 6.8
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow [FC6]
CVE-2007-3387 xpdf integer overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
fixed in koffice-1.6.3-9.fc6
%changelog
* Mon Aug 13 2007 Rex Dieter
1.6.3-9
- CVE-2007-3387 (#251522, #251524)
Bugzilla
CVE-2007-3387 xpdf integer overflow
bugzilla·2007-07-13·CVSS 5.1
CVE-2007-3387 [MEDIUM] CVE-2007-3387 xpdf integer overflow
CVE-2007-3387 xpdf integer overflow
Maurycy Prodeus discovered an integer overflow flaw in the way xpdf processes
PDF files. It's possible this flaw could be used to execute arbitrary code as
the user running the application using the xpdf source.
Discussion:
Created attachment 159239
Proposed upstream fix
---
embargo moved by upstream to Jul 28
---
krh, these packages are affected (I verified them) because of the patch we
applied to fix CVE-2005-3193.
---
These issues should now be considered public.
---
KDE Security Advisory with patches for koffice and kdegraphics:
http://www.kde.org/info/security/advisory-20070730-1.txt
---
poppler-0.5.4-8.fc7 has been submitted as an update for Fedora 7
---
poppler-0.5.4-8.fc7 has been pushed to the Fedora 7 stable repository. If probl
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl1.patchftp://patches.sgi.com/support/free/security/advisories/20070801-01-P.aschttp://bugs.gentoo.org/show_bug.cgi?id=187139http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=248194http://osvdb.org/40127http://secunia.com/advisories/26188http://secunia.com/advisories/26251http://secunia.com/advisories/26254http://secunia.com/advisories/26255http://secunia.com/advisories/26257http://secunia.com/advisories/26278http://secunia.com/advisories/26281http://secunia.com/advisories/26283http://secunia.com/advisories/26292http://secunia.com/advisories/26293http://secunia.com/advisories/26297http://secunia.com/advisories/26307http://secunia.com/advisories/26318http://secunia.com/advisories/26325http://secunia.com/advisories/26342http://secunia.com/advisories/26343http://secunia.com/advisories/26358http://secunia.com/advisories/26365http://secunia.com/advisories/26370http://secunia.com/advisories/26395http://secunia.com/advisories/26403http://secunia.com/advisories/26405http://secunia.com/advisories/26407http://secunia.com/advisories/26410http://secunia.com/advisories/26413http://secunia.com/advisories/26425http://secunia.com/advisories/26432http://secunia.com/advisories/26436http://secunia.com/advisories/26467http://secunia.com/advisories/26468http://secunia.com/advisories/26470http://secunia.com/advisories/26514http://secunia.com/advisories/26607http://secunia.com/advisories/26627http://secunia.com/advisories/26862http://secunia.com/advisories/26982http://secunia.com/advisories/27156http://secunia.com/advisories/27281http://secunia.com/advisories/27308http://secunia.com/advisories/27637http://secunia.com/advisories/30168http://security.gentoo.org/glsa/glsa-200709-12.xmlhttp://security.gentoo.org/glsa/glsa-200709-17.xmlhttp://security.gentoo.org/glsa/glsa-200710-20.xmlhttp://security.gentoo.org/glsa/glsa-200711-34.xmlhttp://security.gentoo.org/glsa/glsa-200805-13.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.761882http://sourceforge.net/project/shownotes.php?release_id=535497http://support.avaya.com/elmodocs2/security/ASA-2007-401.htmhttp://www.debian.org/security/2007/dsa-1347http://www.debian.org/security/2007/dsa-1348http://www.debian.org/security/2007/dsa-1349http://www.debian.org/security/2007/dsa-1350http://www.debian.org/security/2007/dsa-1352http://www.debian.org/security/2007/dsa-1354http://www.debian.org/security/2007/dsa-1355http://www.debian.org/security/2007/dsa-1357http://www.gentoo.org/security/en/glsa/glsa-200710-08.xmlhttp://www.kde.org/info/security/advisory-20070730-1.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2007:158http://www.mandriva.com/security/advisories?name=MDKSA-2007:159http://www.mandriva.com/security/advisories?name=MDKSA-2007:160http://www.mandriva.com/security/advisories?name=MDKSA-2007:161http://www.mandriva.com/security/advisories?name=MDKSA-2007:162http://www.mandriva.com/security/advisories?name=MDKSA-2007:163http://www.mandriva.com/security/advisories?name=MDKSA-2007:164http://www.mandriva.com/security/advisories?name=MDKSA-2007:165http://www.novell.com/linux/security/advisories/2007_15_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_16_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0720.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0729.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0730.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0731.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0732.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0735.htmlhttp://www.securityfocus.com/archive/1/476508/100/0/threadedhttp://www.securityfocus.com/archive/1/476519/30/5400/threadedhttp://www.securityfocus.com/archive/1/476765/30/5340/threadedhttp://www.securityfocus.com/bid/25124http://www.securitytracker.com/id?1018473http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.423670http://www.ubuntu.com/usn/usn-496-1http://www.ubuntu.com/usn/usn-496-2http://www.vupen.com/english/advisories/2007/2704http://www.vupen.com/english/advisories/2007/2705https://issues.foresightlinux.org/browse/FL-471https://issues.rpath.com/browse/RPL-1596https://issues.rpath.com/browse/RPL-1604https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11149ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl1.patchftp://patches.sgi.com/support/free/security/advisories/20070801-01-P.aschttp://bugs.gentoo.org/show_bug.cgi?id=187139http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=248194http://osvdb.org/40127http://secunia.com/advisories/26188
+ 88 more references
2007-07-30
Published