Информационная безопасность
[RU] switch to English


DoS через файлы PDF против библиотек работ с PDF-файлами
дополнено с 18 января 2007 г.
Опубликовано:21 января 2007 г.
Источник:
SecurityVulns ID:7067
Тип:библиотека
Уровень опасности:
5/10
Описание:Бесконечный цикл при разборе дерева моделей страницы.
Затронутые продукты:XPDF : xpdf 3.0
 KDE : KDE 3.4
 ADOBE : Acrobat Reader 7.0
 KDE : koffice 1.4
 POPPLER : poppler 0.4
 PDFTOHTML : pdftohtml 0.36
 TETEX : tetex 3.0
 JADETEX : jadetex 3.12
 APPLE : Preview.app 3.0
CVE:CVE-2007-0104 (The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.)
 CVE-2007-0103 (The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.)
 CVE-2007-0102 (The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.)
Оригинальный текстdocumentMOAB, MOAB-06-01-2007: Multiple Vendor PDF Document Catalog Handling Vulnerability (21.01.2007)
 documentMANDRIVA, [ MDKSA-2007:022 ] - Updated tetex packages fix crafted pdf file vulnerability (19.01.2007)
 documentMANDRIVA, [ MDKSA-2007:021 ] - Updated xpdf packages fix crafted pdf file vulnerability (19.01.2007)
 documentMANDRIVA, [ MDKSA-2007:019 ] - Updated pdftohtml packages fix crafted pdf file vulnerability (19.01.2007)
 documentUBUNTU, [USN-410-1] poppler vulnerability (18.01.2007)
Файлы:Exploits Multiple Vendor PDF Document Catalog Handling Vulnerability

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород