CVE-2007-5392: Buffer Overflow
Published Nov 8, 2007
·Updated
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Affected Software
1 affected component
xpdf Xpdf=3.0.1_pl1
Remediation
Patch Available
Event History
Nov 8, 2007
CVE Published
02:46 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5392?
The severity of CVE-2007-5392 is classified as high due to the potential for remote code execution.
2
How do I fix CVE-2007-5392?
To fix CVE-2007-5392, upgrade to a version of Xpdf that is not vulnerable, as the issue is present in Xpdf 3.0.1_pl1.
3
What are the consequences of CVE-2007-5392 exploitation?
Exploitation of CVE-2007-5392 may allow remote attackers to execute arbitrary code on the affected system.
4
Which versions of Xpdf are affected by CVE-2007-5392?
CVE-2007-5392 affects Xpdf version 3.0.1_pl1 specifically.
5
Can CVE-2007-5392 be exploited through a PDF file?
Yes, CVE-2007-5392 can be exploited by using a crafted PDF file to trigger the vulnerability.