CVE-2007-3387
Published: 07/30/2007 23:17:00
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
MEDIUM
CVSS v2: 6.8
CVSS v2: 6.8
Status
DocFilters Release | Package | State | Justification | Comment |
---|---|---|---|---|
25.1 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.4 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.4.0 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.3 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.2.1 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.2 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.1 | xpdf (3.02) | Resolved | Code Not Present | Patched applied from about:blank |
23.3 | xpdf (3.02) | Resolved | Code Not Present | Patched applied from about:blank |
23.2.1 | xpdf (3.02) | Resolved | Code Not Present | Patched applied from about:blank |
23.2 | xpdf (3.02) | Resolved | Code Not Present | Patched applied from about:blank |
23.1 | xpdf (3.02) | Resolved | Code Not Present | Patched applied from about:blank |