CVE

CVE-2007-4352

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/11/2007
Last modified:
29/09/2017

Description

Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xpdf:xpdf:3.0.1_pl1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools