CVE-2007-0104
Summary
| CVE | CVE-2007-0104 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-09 00:28:00 UTC |
| Updated | 2018-10-16 16:31:00 UTC |
| Description | The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Kde |
Kde |
3.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2.1 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2.3 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.3 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.3.1 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.3.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4.1 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4.3 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.5 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2.1 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.2.3 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.3 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.3.1 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.3.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4.1 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4.2 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.4.3 |
All |
All |
All |
| Operating System |
Kde |
Kde |
3.5 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0.1 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0.1_pl1 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0.1_pl2 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0_pl2 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0.1 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0.1_pl1 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0.1_pl2 |
All |
All |
All |
| Application |
Xpdf |
Xpdf |
3.0_pl2 |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| Webmail - OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| Ubuntu update for poppler - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| rPath update for poppler - Secunia Advisories - Vulnerability Intelligence - Secunia.com |
SECUNIA |
secunia.com |
Vendor Advisory |
| About the security content of Mac OS X 10.4.9 and Security Update 2007-003 |
CONFIRM |
docs.info.apple.com |
|
| www.kde.org/info/security/advisory-20070115-1.txt |
CONFIRM |
www.kde.org |
|
| Mandriva update for poppler - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Mandriva update for tetex - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| issues.rpath.com/browse/RPL-964 |
CONFIRM |
issues.rpath.com |
|
| SUSE update for poppler - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Mandriva update for koffice - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA07-072A -- Apple Updates for Multiple Vulnerabilities |
CERT |
www.us-cert.gov |
US Government Resource |
| Multiple PDF Readers Multiple Remote Buffer Overflow Vulnerability |
BID |
www.securityfocus.com |
Exploit |
| Webmail - OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| Webmail - OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| Apple Mac OS X CoreGraphics PDF File Processing Bug Lets Remote Users Deny Service - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| Mandriva update for kdegraphics - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| MOAB-06-01-2007: Multiple Vendor PDF Document Catalog Handling Vulnerability |
MISC |
projects.info-pull.com |
|
| Security update for poppler |
CONFIRM |
support.novell.com |
|
| Poppler Invalid Tree Node Denial of Service - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| USN-410-1: poppler vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| SecurityFocus |
BUGTRAQ |
www.securityfocus.com |
|
| USN-410-2: teTeX vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Webmail - OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| SecurityTracker.com Archives - KDE kpdf Bug Lets Remote Users Deny Service |
SECTRACK |
securitytracker.com |
|
| IBM X-Force Exchange |
XF |
exchange.xforce.ibmcloud.com |
|
| Security Announcement |
SUSE |
www.novell.com |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| KDE and KOffice PDF Invalid Tree Node Denial of Service Weakness - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2007-01-15 | Joshua Bressers | Not Vulnerable. This flaw is the result of an infinite recursion flaw in xpdf, which cannot result in arbitrary code execution. |
There are currently no legacy QID mappings associated with this CVE.