[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1537 xpdf -- several vulnerabilities

ID: oval:org.mitre.oval:def:7985Date: (C)2009-12-15   (M)2021-06-02
Class: PATCHFamily: unix




Alin Rad Pop (Secunia) discovered a number of vulnerabilities in xpdf, a set of tools for display and conversion of Portable Document Format (PDF) files. The Common Vulnerabilities and Exposures project identifies the following three problems: Inadequate DCT stream validation allows an attacker to corrupt memory and potentially execute arbitrary code by supplying a maliciously crafted PDF file. An integer overflow vulnerability in DCT stream handling could allow an attacker to overflow a heap buffer, enabling the execution of arbitrary code. A buffer overflow vulnerability in xpdf's CCITT image compression handlers allows overflow on the heap, allowing an attacker to execute arbitrary code by supplying a maliciously crafted CCITTFaxDecode filter.

Platform:
Debian 4.0
Product:
xpdf
Reference:
DSA-1537
CVE-2007-4352
CVE-2007-5392
CVE-2007-5393
CVE    3
CVE-2007-4352
CVE-2007-5392
CVE-2007-5393
CPE    1
cpe:/o:debian:debian_linux:4.x

© SecPod Technologies