CVE-2007-5392
EPSS 6.6%Published: 11/8/2007Modified: 4/28/2026
Also known as:DEBIAN-CVE-2007-5392
Description
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Affected packages (4)
- Debian/cupsfrom 0, < 1.1.22-7
- Debian/libextractorfrom 0, < 0.5.12-1
- Debian/popplerfrom 0, < 0.6.2-1
- Debian/xpdffrom 0, < 3.02-1.3