DCTStream:: reset()
Published Nov 8, 2007
9.3
HIGHCVSS 2.0
EPSS 6.41%
Description
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
xpdf-1:2.02-11.el3
Fixed · RHSA-2007:1030
Red Hat Enterprise Linux 4
cups-1:1.1.22-0.rc1.9.20.2.el4_5.2
Fixed · RHSA-2007:1022
Red Hat Enterprise Linux 4
gpdf-0:2.8.2-7.7.1
Fixed · RHSA-2007:1025
Red Hat Enterprise Linux 4
kdegraphics-7:3.3.1-6.el4_5
Fixed · RHSA-2007:1024
Red Hat Enterprise Linux 4
tetex-0:2.0.2-22.0.1.EL4.10
Fixed · RHSA-2007:1027
Red Hat Enterprise Linux 4
xpdf-1:3.00-14.el4
Fixed · RHSA-2007:1029
Red Hat Enterprise Linux 5
cups-1:1.2.4-11.14.el5_1.3
Fixed · RHSA-2007:1021
Red Hat Enterprise Linux 5
poppler-0:0.5.4-4.3.el5_1
Fixed · RHSA-2007:1026
Red Hat Enterprise Linux 5
tetex-0:3.0-33.2.el5_1.2
Fixed · RHSA-2007:1027
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | xpdf-1:2.02-11.el3 | Fixed | RHSA-2007:1030 |
| Red Hat Enterprise Linux 4 | cups-1:1.1.22-0.rc1.9.20.2.el4_5.2 | Fixed | RHSA-2007:1022 |
| Red Hat Enterprise Linux 4 | gpdf-0:2.8.2-7.7.1 | Fixed | RHSA-2007:1025 |
| Red Hat Enterprise Linux 4 | kdegraphics-7:3.3.1-6.el4_5 | Fixed | RHSA-2007:1024 |
| Red Hat Enterprise Linux 4 | tetex-0:2.0.2-22.0.1.EL4.10 | Fixed | RHSA-2007:1027 |
| Red Hat Enterprise Linux 4 | xpdf-1:3.00-14.el4 | Fixed | RHSA-2007:1029 |
| Red Hat Enterprise Linux 5 | cups-1:1.2.4-11.14.el5_1.3 | Fixed | RHSA-2007:1021 |
| Red Hat Enterprise Linux 5 | poppler-0:0.5.4-4.3.el5_1 | Fixed | RHSA-2007:1026 |
| Red Hat Enterprise Linux 5 | tetex-0:3.0-33.2.el5_1.2 | Fixed | RHSA-2007:1027 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.41% (0.06408) | 93.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.41% (0.06408) | 92.77th | v5 (v2026.06.15) |
| Jan 23, 2026 | 6.57% (0.06567) | 90.89th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.23% (0.04225) | 87.70th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.89% (0.07890) | 86.44th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.23% (0.04225) | 88.01th | v4 (v2025.03.14) |
| Dec 17, 2024 | 20.10% (0.20104) | 96.34th | v3 (v2023.03.01) |
| Oct 19, 2024 | 15.23% (0.15226) | 95.97th | v3 (v2023.03.01) |
| Sep 11, 2024 | 12.08% (0.12077) | 95.49th | v3 (v2023.03.01) |
| Aug 4, 2024 | 14.30% (0.14296) | 95.75th | v3 (v2023.03.01) |
| Jun 27, 2024 | 16.45% (0.16445) | 96.05th | v3 (v2023.03.01) |
| May 20, 2024 | 13.39% (0.13389) | 95.58th | v3 (v2023.03.01) |
| Apr 11, 2024 | 16.34% (0.16337) | 95.89th | v3 (v2023.03.01) |
| Mar 7, 2023 | 12.93% (0.12931) | 94.57th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.43% (0.12433) | 95.34th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.43% (0.12433) | 94.97th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.43% (0.12433) | 89.48th | v2 (v2022.01.01) |
References (86)
- http://secunia.com/advisories/26503 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27260 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/27553 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27573 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27574 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27575 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27577 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27578 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27599 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27615 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27618 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27619 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27632 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27634 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27636 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27637 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27640 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/27641 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27642 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27645 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27656 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27658 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27705 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27721 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27724 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27743 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27856 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28043 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28812 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29104 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29604 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30168 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/secunia_research/2007-88/advisory/ x_refsource_MISCVendor Advisory
- http://security.gentoo.org/glsa/glsa-200711-22.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200711-34.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200805-13.xml vendor-advisoryx_refsource_GENTOO
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.761882 vendor-advisoryx_refsource_SLACKWARE
- http://support.novell.com/techcenter/psdb/1d5fd29802b2ef7e342e733731f1e933.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/3867a5092daac43cd6a92e6107d9fbce.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/43ad7b3569dba59e7ba07677edc01cad.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/da3498f05433976cc548cc4eaf8349c8.html x_refsource_CONFIRM
- http://support.novell.com/techcenter/psdb/f83e024a65d69ebc810d2117815b940d.html x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1480 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1509 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1537 vendor-advisoryx_refsource_DEBIAN
- http://www.kde.org/info/security/advisory-20071107-1.txt x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:219 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:220 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:221 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:222 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:223 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:227 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:228 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:230 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_60_pdf.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2007-1021.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1022.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1024.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1025.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1026.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1027.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1029.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1030.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/archive/1/483372 mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/26367 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018905 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-542-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-542-2 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2007/3774 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3775 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3776 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3779 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3786 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-5392 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=345111 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38303 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1926 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-5392
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10036 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-5392
- https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00369.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00215.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00224.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00238.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00724.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.