Out-of-bounds read In poppler
Description
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 0.4.3-2 | ||
debian 13 | 1.1.23-13 | ||
debian 11 | 0.5.8-1 | ||
debian 12 | 0.5.8-1 | ||
debian 13 | 3.01-3 | ||
debian 14 | 1.1.23-13 | ||
debian 11 | 0.4.3-2 | ||
debian 14 | 0.4.3-2 | ||
debian 11 | 3.01-3 | ||
debian 12 | 3.01-3 |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5.