CVE-2007-4352
Publication date 7 November 2007
Last updated 24 July 2024
Ubuntu priority
Description
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gpdf | ||
| cups | ||
| ipe | ||
| cupsys | ||
| kdegraphics | ||
| koffice | ||
| libextractor | ||
| pdfkit.framework | ||
| pdftohtml | ||
| poppler | ||
| tetex-bin | ||
| texlive-bin | ||
| xpdf | ||
Notes
Patch details
| Package | Patch details |
|---|---|
| xpdf |