DCTStream:: readProgressiveDataUnit()
Published Nov 8, 2007
7.6
HIGHCVSS 2.0
EPSS 7.02%
Description
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
xpdf-1:2.02-11.el3
Fixed · RHSA-2007:1030
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.20.2.el4_5.2
Fixed · RHSA-2007:1022
Red Hat Enterprise Linux 4
gpdf-0:2.8.2-7.7.1
Fixed · RHSA-2007:1025
Red Hat Enterprise Linux 4
kdegraphics-7:3.3.1-6.el4_5
Fixed · RHSA-2007:1024
Red Hat Enterprise Linux 4
tetex-0:2.0.2-22.0.1.EL4.10
Fixed · RHSA-2007:1027
Red Hat Enterprise Linux 4
xpdf-1:3.00-14.el4
Fixed · RHSA-2007:1029
Red Hat Enterprise Linux 5
cups-1:1.2.4-11.14.el5_1.3
Fixed · RHSA-2007:1021
Red Hat Enterprise Linux 5
poppler-0:0.5.4-4.3.el5_1
Fixed · RHSA-2007:1026
Red Hat Enterprise Linux 5
tetex-0:3.0-33.2.el5_1.2
Fixed · RHSA-2007:1027
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | xpdf-1:2.02-11.el3 | Fixed | RHSA-2007:1030 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.20.2.el4_5.2 | Fixed | RHSA-2007:1022 |
| Red Hat Enterprise Linux 4 | gpdf-0:2.8.2-7.7.1 | Fixed | RHSA-2007:1025 |
| Red Hat Enterprise Linux 4 | kdegraphics-7:3.3.1-6.el4_5 | Fixed | RHSA-2007:1024 |
| Red Hat Enterprise Linux 4 | tetex-0:2.0.2-22.0.1.EL4.10 | Fixed | RHSA-2007:1027 |
| Red Hat Enterprise Linux 4 | xpdf-1:3.00-14.el4 | Fixed | RHSA-2007:1029 |
| Red Hat Enterprise Linux 5 | cups-1:1.2.4-11.14.el5_1.3 | Fixed | RHSA-2007:1021 |
| Red Hat Enterprise Linux 5 | poppler-0:0.5.4-4.3.el5_1 | Fixed | RHSA-2007:1026 |
| Red Hat Enterprise Linux 5 | tetex-0:3.0-33.2.el5_1.2 | Fixed | RHSA-2007:1027 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 7.02% (0.07020) | 93.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.02% (0.07020) | 93.32th | v5 (v2026.06.15) |
| Dec 1, 2025 | 25.47% (0.25469) | 96.03th | v4 (v2025.03.14) |
| Sep 26, 2025 | 16.13% (0.16135) | 94.58th | v4 (v2025.03.14) |
| Jun 24, 2025 | 18.81% (0.18813) | 94.95th | v4 (v2025.03.14) |
| Mar 30, 2025 | 21.67% (0.21673) | 95.24th | v4 (v2025.03.14) |
| Mar 29, 2025 | 26.90% (0.26902) | 94.18th | v4 (v2025.03.14) |
| Mar 21, 2025 | 21.67% (0.21673) | 95.27th | v4 (v2025.03.14) |
| Mar 17, 2025 | 18.81% (0.18813) | 94.81th | v4 (v2025.03.14) |
| Feb 11, 2025 | 25.27% (0.25267) | 96.74th | v3 (v2023.03.01) |
| Dec 17, 2024 | 19.53% (0.19532) | 96.29th | v3 (v2023.03.01) |
| Oct 19, 2024 | 17.62% (0.17618) | 96.24th | v3 (v2023.03.01) |
| Sep 11, 2024 | 19.84% (0.19836) | 96.43th | v3 (v2023.03.01) |
| Aug 4, 2024 | 17.67% (0.17671) | 96.16th | v3 (v2023.03.01) |
| Jun 27, 2024 | 13.87% (0.13867) | 95.69th | v3 (v2023.03.01) |
| Apr 11, 2024 | 13.45% (0.13450) | 95.49th | v3 (v2023.03.01) |
| Nov 13, 2023 | 12.36% (0.12360) | 94.85th | v3 (v2023.03.01) |
| Oct 8, 2023 | 12.02% (0.12023) | 94.69th | v3 (v2023.03.01) |
| Mar 7, 2023 | 11.43% (0.11427) | 94.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.43% (0.12433) | 95.34th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.43% (0.12433) | 94.97th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.43% (0.12433) | 89.48th | v2 (v2022.01.01) |
No CWE recorded.
References (86)
- http://secunia.com/advisories/26503 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27260 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/27553 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27573 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27574 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27575 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27577 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27578 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27599 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27615 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27618 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27619 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27632 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27634 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27636 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27637 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27640 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27641 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27642 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27645 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27656 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27658 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27705 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27721 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27724 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27743 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27856 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28043 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28812 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29104 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29604 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30168 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/secunia_research/2007-88/advisory/ x_refsource_MISCVendor Advisory
- http://security.gentoo.org/glsa/glsa-200711-22.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200711-34.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200805-13.xml vendor-advisoryx_refsource_GENTOO
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.761882 vendor-advisoryx_refsource_SLACKWARE
- http://support.novell.com/techcenter/psdb/1d5fd29802b2ef7e342e733731f1e933.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/3867a5092daac43cd6a92e6107d9fbce.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/43ad7b3569dba59e7ba07677edc01cad.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/da3498f05433976cc548cc4eaf8349c8.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/f83e024a65d69ebc810d2117815b940d.html x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1480 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1509 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1537 vendor-advisoryx_refsource_DEBIAN
- http://www.kde.org/info/security/advisory-20071107-1.txt x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:219 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:220 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:221 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:222 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:223 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:227 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:228 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:230 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_60_pdf.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2007-1021.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1022.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1024.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1025.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1026.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1027.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1029.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1030.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/483372 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/26367 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018905 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-542-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-542-2 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2007/3774 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3775 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3776 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3779 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3786 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-4352 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=345101 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38306 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1926 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-4352
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9979 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-4352
- https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00369.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00215.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00224.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00238.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00724.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.