CVE-2007-5393Improper Restriction of Operations within the Bounds of a Memory Buffer in Xpdf

Severity
9.3CRITICALNVD
EPSS
14.2%
top 5.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 8
Latest updateMay 1

Description

Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

Debianxpdf/xpdf< 3.02-1.3+3
NVDxpdf/xpdf3.02p11
Debianapple/cups< 1.1.22-7+3
Debiangnu/libextractor< 0.5.12-1+3
Debianfreedesktop/poppler< 0.6.2-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jvj2-mwv2-mvpr: Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream2022-05-01
CVEList
CVE-2007-5393: Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream2007-11-08
OSV
CVE-2007-5393: Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream2007-11-08

📋Vendor Advisories

4
Ubuntu
KOffice vulnerabilities2007-11-15
Ubuntu
poppler vulnerabilities2007-11-14
Red Hat
CCITTFaxStream:: lookChar()2007-11-07
Debian
CVE-2007-5393: cups - Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream...2007

💬Community

1
Bugzilla
CVE-2007-5393 xpdf buffer overflow in CCITTFaxStream::lookChar()2007-10-22
CVE-2007-5393 — Xpdf vulnerability | cvebase