CVE-2007-0104

NameCVE-2007-0104
DescriptionThe Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs406852

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)jessie, jessie (lts)0.26.5-2+deb8u16fixed
stretch (security)0.48.0-2+deb9u4fixed
stretch (lts), stretch0.48.0-2+deb9u6fixed
buster (security), buster, buster (lts)0.71.0-5+deb10u3fixed
bullseye (security), bullseye20.09.0-3.1+deb11u1fixed
bookworm22.12.0-2fixed
sid, trixie24.08.0-3fixed
swftools (PTS)jessie0.9.2+git20130725-2fixed
stretch0.9.2+git20130725-4.1fixed
xpdf (PTS)jessie3.03-17fixed
stretch3.04-4fixed
buster3.04-13fixed
bullseye3.04+git20210103-3fixed
bookworm3.04+git20220601-1fixed
sid, trixie3.04+git20240613-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kdegraphicssource(unstable)4:3.5.5-3unimportant
kofficesource(unstable)(unfixed)unimportant
popplersource(unstable)0.4.5-5.1unimportant
swftoolssource(unstable)(not affected)
xpdfsource(unstable)3.02unimportant406852

Notes

- swftools <not-affected> (first version that entered the archive is based on xpdf 3.02)
hardly a security issue; if someone sends someone a crafted PDF file triggering
such an endless loop the user will simply abort kpdf and never look at
that file again, this is only denial of service by a _very_ far stretch
of imagination. I suppose KDE Security only issued an update for it
because the shared underlying code was part of the Month of Apple Bugs
and they wanted to debunk claims of code injection.

Search for package or bug name: Reporting problems