Impact
remote code execution
Solution
Please Install the Updated Packages.
Insight
Secunia Research reported three security bugs in xpdf.
The first problem occurs while indexing an array in DCTStream::
readProgressiveDataUnit() and is tracked by CVE-2007-4352. Another method in the same class named reset() is vulnerable to an integer overflow which leads to an overflow on the heap, CVE-2007-5392. The last bug also causes an overflow on the heap but this time in method lookChar() of class CCITTFaxStream, CVE-2007-5393.
All three bugs can be exploited remotely with a crafted PDF file with user- assistance only.
These bugs do not only affect xpdf but also the following packages:
kdegraphics3-pdf, koffice, libextractor, poppler, gpdf, cups, pdf, pdftohtml
Affected
xpdf, kdegraphics3-pdf, koffice, libextractor, on SUSE LINUX 10.1, openSUSE 10.2, openSUSE 10.3, SuSE Linux Enterprise Server 8, SUSE SLES 9, Novell Linux Desktop 9, Open Enterprise Server, Novell Linux POS 9, SUSE Linux Enterprise Desktop 10 SP1, SLE SDK 10 SP1, SUSE Linux Enterprise Server 10 SP1
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2007-4352, CVE-2007-5392, CVE-2007-5393 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities