CVE-2007-3387: Buffer Overflow
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3387?
The severity of CVE-2007-3387 is classified as critical, as it allows remote code execution through crafted PDF files.
How do I fix CVE-2007-3387?
To fix CVE-2007-3387, upgrade affected software to versions that have resolved this vulnerability, such as updated versions of Xpdf, Poppler, gpdf, and CUPS.
Which software is affected by CVE-2007-3387?
CVE-2007-3387 affects several software products, including Xpdf 3.02, Poppler versions before 0.5.91, gpdf versions before 2.8.2, and various others.
Can CVE-2007-3387 be exploited remotely?
Yes, CVE-2007-3387 can be exploited remotely by attackers using maliciously crafted PDF files.
What platforms are affected by CVE-2007-3387?
CVE-2007-3387 affects multiple platforms, including Debian and Ubuntu distributions, specifically versions 3.1, 4.0, and various 6.x to 7.x releases.