CVE-2007-0104
Summary
| CVE | CVE-2007-0104 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-09 00:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Kde | Kde | 3.2 | All | All | All |
| Operating System | Kde | Kde | 3.2.1 | All | All | All |
| Operating System | Kde | Kde | 3.2.2 | All | All | All |
| Operating System | Kde | Kde | 3.2.3 | All | All | All |
| Operating System | Kde | Kde | 3.3 | All | All | All |
| Operating System | Kde | Kde | 3.3.1 | All | All | All |
| Operating System | Kde | Kde | 3.3.2 | All | All | All |
| Operating System | Kde | Kde | 3.4 | All | All | All |
| Operating System | Kde | Kde | 3.4.1 | All | All | All |
| Operating System | Kde | Kde | 3.4.2 | All | All | All |
| Operating System | Kde | Kde | 3.4.3 | All | All | All |
| Operating System | Kde | Kde | 3.5 | All | All | All |
| Application | Xpdf | Xpdf | 3.0 | All | All | All |
| Application | Xpdf | Xpdf | 3.0.1 | All | All | All |
| Application | Xpdf | Xpdf | 3.0.1_pl1 | All | All | All |
| Application | Xpdf | Xpdf | 3.0.1_pl2 | All | All | All |
| Application | Xpdf | Xpdf | 3.0_pl2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Mandriva update for kdegraphics - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Mandriva update for poppler - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| rPath update for poppler - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| www.kde.org/info/security/advisory-20070115-1.txt | af854a3a-2127-422b-91ae-364da2661108 | www.kde.org | |
| MOAB-06-01-2007: Multiple Vendor PDF Document Catalog Handling Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | projects.info-pull.com | |
| US-CERT Technical Cyber Security Alert TA07-072A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Mandriva update for koffice - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Mandriva update for tetex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| About the security content of Mac OS X 10.4.9 and Security Update 2007-003 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| issues.rpath.com/browse/RPL-964 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| USN-410-1: poppler vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Poppler Invalid Tree Node Denial of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Ubuntu update for poppler - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security update for poppler | af854a3a-2127-422b-91ae-364da2661108 | support.novell.com | |
| Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Apple Mac OS X CoreGraphics PDF File Processing Bug Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SUSE update for poppler - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - KDE kpdf Bug Lets Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| USN-410-2: teTeX vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| KDE and KOffice PDF Invalid Tree Node Denial of Service Weakness - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-01-15 | Joshua Bressers | Not Vulnerable. This flaw is the result of an infinite recursion flaw in xpdf, which cannot result in arbitrary code execution. |
There are currently no legacy QID mappings associated with this CVE.