CVE-2007-4352: High severity xpdf Xpdf vulnerability
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4352?
CVE-2007-4352 is categorized as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2007-4352?
To fix CVE-2007-4352, update to the latest version of Xpdf and ensure all affected software are also patched.
What products are affected by CVE-2007-4352?
CVE-2007-4352 affects Xpdf 3.02pl1 and products that incorporate it, including poppler, teTeX, KDE, KOffice, and CUPS.
What type of vulnerability is CVE-2007-4352?
CVE-2007-4352 is an array index error that can lead to memory corruption and arbitrary code execution.
Can CVE-2007-4352 be exploited remotely?
Yes, CVE-2007-4352 can be exploited remotely via crafted PDF files.