Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2007-07-30 16:17
Updated : 2023-02-12 18:17
NVD link : CVE-2007-3387
Mitre link : CVE-2007-3387
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
apple
- cups
freedesktop
- poppler
gpdf_project
- gpdf
canonical
- ubuntu_linux
xpdfreader
- xpdf
debian
- debian_linux