{ "id": "CVE-2007-5392", "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com", "published": "2007-11-08T02:46:00.000", "lastModified": "2017-09-29T01:29:36.173", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow." }, { "lang": "es", "value": "Un desbordamiento de enteros en el m\u00e9todo DCTStream::reset en el archivo xpdf/Stream.cc en Xpdf versi\u00f3n 3.02p11, permite a atacantes remotos ejecutar c\u00f3digo arbitrario por medio de un archivo PDF dise\u00f1ado, resultando en un desbordamiento de b\u00fafer en la regi\u00f3n heap de la memoria." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 9.3 }, "baseSeverity": "HIGH", "exploitabilityScore": 8.6, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": true, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-119" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:xpdf:xpdf:3.0.1_pl1:*:*:*:*:*:*:*", "matchCriteriaId": "B0A09900-C462-4E3D-9399-0271F91DC5BD" } ] } ] } ], "references": [ { "url": "http://security.gentoo.org/glsa/glsa-200711-22.xml", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://security.gentoo.org/glsa/glsa-200711-34.xml", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://security.gentoo.org/glsa/glsa-200805-13.xml", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.761882", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://support.novell.com/techcenter/psdb/1d5fd29802b2ef7e342e733731f1e933.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://support.novell.com/techcenter/psdb/3867a5092daac43cd6a92e6107d9fbce.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://support.novell.com/techcenter/psdb/43ad7b3569dba59e7ba07677edc01cad.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://support.novell.com/techcenter/psdb/da3498f05433976cc548cc4eaf8349c8.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://support.novell.com/techcenter/psdb/f83e024a65d69ebc810d2117815b940d.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.debian.org/security/2008/dsa-1480", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.debian.org/security/2008/dsa-1509", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.debian.org/security/2008/dsa-1537", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.kde.org/info/security/advisory-20071107-1.txt", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:219", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:220", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:221", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:222", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:223", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:227", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:228", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:230", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.novell.com/linux/security/advisories/2007_60_pdf.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1021.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1022.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1024.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1025.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1026.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1027.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1029.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.redhat.com/support/errata/RHSA-2007-1030.html", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/archive/1/483372", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.securityfocus.com/bid/26367", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.securitytracker.com/id?1018905", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.ubuntu.com/usn/usn-542-1", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.ubuntu.com/usn/usn-542-2", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.vupen.com/english/advisories/2007/3774", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.vupen.com/english/advisories/2007/3775", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.vupen.com/english/advisories/2007/3776", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.vupen.com/english/advisories/2007/3779", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "http://www.vupen.com/english/advisories/2007/3786", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38303", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://issues.rpath.com/browse/RPL-1926", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10036", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00369.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00215.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00224.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00238.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html", "source": "PSIRT-CNA@flexerasoftware.com" }, { "url": "https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00724.html", "source": "PSIRT-CNA@flexerasoftware.com" } ] }