CVE-2007-5392
published 2007-11-08CVE-2007-5392: Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.41%
92.9th percentile
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| apple | cups | >= 0 < 1.1.22-7 | 1.1.22-7 |
| debian | cups | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | libextractor | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | poppler | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| debian | xpdf | < cups 1.1.22-7 (bookworm) | cups 1.1.22-7 (bookworm) |
| freedesktop | poppler | >= 0 < 0.6.2-1 | 0.6.2-1 |
| freedesktop | poppler | >= 0 < 0.6.2-1 | 0.6.2-1 |
| freedesktop | poppler | >= 0 < 0.6.2-1 | 0.6.2-1 |
| freedesktop | poppler | >= 0 < 0.6.2-1 | 0.6.2-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| gnu | libextractor | >= 0 < 0.5.12-1 | 0.5.12-1 |
| xpdf | xpdf | — | — |
| xpdf | xpdf | >= 0 < 3.02-1.3 | 3.02-1.3 |
| xpdf | xpdf | >= 0 < 3.02-1.3 | 3.02-1.3 |
| xpdf | xpdf | >= 0 < 3.02-1.3 | 3.02-1.3 |
| xpdf | xpdf | >= 0 < 3.02-1.3 | 3.02-1.3 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KOffice vulnerabilities
vendor_ubuntu·2007-11-15
CVE-2007-4352 KOffice vulnerabilities
Title: KOffice vulnerabilities
Summary: KOffice vulnerabilities
USN-542-1 fixed a vulnerability in poppler. This update provides the
corresponding updates for KWord, part of KOffice.
Original advisory details:
Secunia Research discovered several vulnerabilities in poppler. If a
user were tricked into loading a specially crafted PDF file, a remote
attacker could cause a denial of service or possibly execute arbitrary
code with the user's privileges in applications linked against poppler.
Instructions: After a standard system upgrade you need to restart KOffice to effect
the necessary changes.
Ubuntu
poppler vulnerabilities
vendor_ubuntu·2007-11-14
CVE-2007-5392 poppler vulnerabilities
Title: poppler vulnerabilities
Summary: poppler vulnerabilities
Secunia Research discovered several vulnerabilities in poppler. If a
user were tricked into loading a specially crafted PDF file, a remote
attacker could cause a denial of service or possibly execute arbitrary
code with the user's privileges in applications linked against poppler.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
DCTStream:: reset()
vendor_redhat·2007-11-07·CVSS 9.3
CVE-2007-5392 [CRITICAL] DCTStream:: reset()
DCTStream:: reset()
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Debian
CVE-2007-5392: cups - Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p1...
vendor_debian·2007·CVSS 9.3
CVE-2007-5392 [CRITICAL] CVE-2007-5392: cups - Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p1...
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fixed in 1.1.22-7)
trixie: resolved (fixed in 1.1.22-7)
GHSA
GHSA-5wjr-7h39-qr5r: Integer overflow in the DCTStream::reset method in xpdf/Stream
ghsa_unreviewed·2022-05-01
CVE-2007-5392 [HIGH] CWE-119 GHSA-5wjr-7h39-qr5r: Integer overflow in the DCTStream::reset method in xpdf/Stream
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
OSV
CVE-2007-5392: Integer overflow in the DCTStream::reset method in xpdf/Stream
osv·2007-11-08·CVSS 9.3
CVE-2007-5392 [CRITICAL] CVE-2007-5392: Integer overflow in the DCTStream::reset method in xpdf/Stream
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/26503http://secunia.com/advisories/27260http://secunia.com/advisories/27553http://secunia.com/advisories/27573http://secunia.com/advisories/27574http://secunia.com/advisories/27575http://secunia.com/advisories/27577http://secunia.com/advisories/27578http://secunia.com/advisories/27599http://secunia.com/advisories/27615http://secunia.com/advisories/27618http://secunia.com/advisories/27619http://secunia.com/advisories/27632http://secunia.com/advisories/27634http://secunia.com/advisories/27636http://secunia.com/advisories/27637http://secunia.com/advisories/27640http://secunia.com/advisories/27641http://secunia.com/advisories/27642http://secunia.com/advisories/27645http://secunia.com/advisories/27656http://secunia.com/advisories/27658http://secunia.com/advisories/27705http://secunia.com/advisories/27721http://secunia.com/advisories/27724http://secunia.com/advisories/27743http://secunia.com/advisories/27856http://secunia.com/advisories/28043http://secunia.com/advisories/28812http://secunia.com/advisories/29104http://secunia.com/advisories/29604http://secunia.com/advisories/30168http://secunia.com/secunia_research/2007-88/advisory/http://security.gentoo.org/glsa/glsa-200711-22.xmlhttp://security.gentoo.org/glsa/glsa-200711-34.xmlhttp://security.gentoo.org/glsa/glsa-200805-13.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.761882http://support.novell.com/techcenter/psdb/1d5fd29802b2ef7e342e733731f1e933.htmlhttp://support.novell.com/techcenter/psdb/3867a5092daac43cd6a92e6107d9fbce.htmlhttp://support.novell.com/techcenter/psdb/43ad7b3569dba59e7ba07677edc01cad.htmlhttp://support.novell.com/techcenter/psdb/da3498f05433976cc548cc4eaf8349c8.htmlhttp://support.novell.com/techcenter/psdb/f83e024a65d69ebc810d2117815b940d.htmlhttp://www.debian.org/security/2008/dsa-1480http://www.debian.org/security/2008/dsa-1509http://www.debian.org/security/2008/dsa-1537http://www.kde.org/info/security/advisory-20071107-1.txthttp://www.mandriva.com/security/advisories?name=MDKSA-2007:219http://www.mandriva.com/security/advisories?name=MDKSA-2007:220http://www.mandriva.com/security/advisories?name=MDKSA-2007:221http://www.mandriva.com/security/advisories?name=MDKSA-2007:222http://www.mandriva.com/security/advisories?name=MDKSA-2007:223http://www.mandriva.com/security/advisories?name=MDKSA-2007:227http://www.mandriva.com/security/advisories?name=MDKSA-2007:228http://www.mandriva.com/security/advisories?name=MDKSA-2007:230http://www.novell.com/linux/security/advisories/2007_60_pdf.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1021.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1022.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1024.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1025.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1026.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1027.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1029.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1030.htmlhttp://www.securityfocus.com/archive/1/483372http://www.securityfocus.com/bid/26367http://www.securitytracker.com/id?1018905http://www.ubuntu.com/usn/usn-542-1http://www.ubuntu.com/usn/usn-542-2http://www.vupen.com/english/advisories/2007/3774http://www.vupen.com/english/advisories/2007/3775http://www.vupen.com/english/advisories/2007/3776http://www.vupen.com/english/advisories/2007/3779http://www.vupen.com/english/advisories/2007/3786https://exchange.xforce.ibmcloud.com/vulnerabilities/38303https://issues.rpath.com/browse/RPL-1926https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10036https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00369.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00215.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00224.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00238.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00724.htmlhttp://secunia.com/advisories/26503http://secunia.com/advisories/27260http://secunia.com/advisories/27553http://secunia.com/advisories/27573http://secunia.com/advisories/27574http://secunia.com/advisories/27575http://secunia.com/advisories/27577http://secunia.com/advisories/27578http://secunia.com/advisories/27599http://secunia.com/advisories/27615http://secunia.com/advisories/27618http://secunia.com/advisories/27619http://secunia.com/advisories/27632http://secunia.com/advisories/27634http://secunia.com/advisories/27636http://secunia.com/advisories/27637http://secunia.com/advisories/27640http://secunia.com/advisories/27641
+ 64 more references
2007-11-08
Published