CVE-2007-5392
Publication date 7 November 2007
Last updated 24 July 2024
Ubuntu priority
Description
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| cups | ||
| cupsys | ||
| gpdf | ||
| ipe | ||
| kdegraphics | ||
| koffice | ||
| libextractor | ||
| pdfkit.framework | ||
| pdftohtml | ||
| poppler | ||
| tetex-bin | ||
| texlive-bin | ||
| xpdf | ||
Notes
Patch details
| Package | Patch details |
|---|---|
| xpdf |