First published: Thu Nov 08 2007(Updated: )
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | =3.0.1_pl1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4352 is categorized as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-4352, update to the latest version of Xpdf and ensure all affected software are also patched.
CVE-2007-4352 affects Xpdf 3.02pl1 and products that incorporate it, including poppler, teTeX, KDE, KOffice, and CUPS.
CVE-2007-4352 is an array index error that can lead to memory corruption and arbitrary code execution.
Yes, CVE-2007-4352 can be exploited remotely via crafted PDF files.