First published: Thu Nov 08 2007(Updated: )
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | =3.02p11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5393 is rated as high severity due to its potential to allow remote code execution.
To fix CVE-2007-5393, upgrade to a patched version of Xpdf that addresses this vulnerability.
CVE-2007-5393 is classified as a heap-based buffer overflow vulnerability.
CVE-2007-5393 affects users running Xpdf version 3.02p11.
The exploit vector for CVE-2007-5393 is a specially crafted PDF file containing a CCITTFaxDecode filter.