Computer Security
[EN] securityvulns.ru no-pyccku


Multiple PDF library PDF parsing DoS
updated since 18.01.2007
Published:21.01.2007
Source:
SecurityVulns ID:7067
Type:library
Threat Level:
5/10
Description:Infinite loop on page model tree parsing.
Affected:XPDF : xpdf 3.0
 KDE : KDE 3.4
 ADOBE : Acrobat Reader 7.0
 KDE : koffice 1.4
 POPPLER : poppler 0.4
 PDFTOHTML : pdftohtml 0.36
 TETEX : tetex 3.0
 JADETEX : jadetex 3.12
 APPLE : Preview.app 3.0
CVE:CVE-2007-0104 (The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.)
 CVE-2007-0103 (The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.)
 CVE-2007-0102 (The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.)
Original documentdocumentMOAB, MOAB-06-01-2007: Multiple Vendor PDF Document Catalog Handling Vulnerability (21.01.2007)
 documentMANDRIVA, [ MDKSA-2007:022 ] - Updated tetex packages fix crafted pdf file vulnerability (19.01.2007)
 documentMANDRIVA, [ MDKSA-2007:021 ] - Updated xpdf packages fix crafted pdf file vulnerability (19.01.2007)
 documentMANDRIVA, [ MDKSA-2007:019 ] - Updated pdftohtml packages fix crafted pdf file vulnerability (19.01.2007)
 documentUBUNTU, [USN-410-1] poppler vulnerability (18.01.2007)
Files:Exploits Multiple Vendor PDF Document Catalog Handling Vulnerability

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod