suse · CVE-2007-4352

Quick triage

Priority: high Published: 2021-05-30 12:39:51 UTC Updated: 2026-04-18 20:32:23 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-4352 severity important: SUSE including 86 source package names (cups-1.3.9-8.30.1, cups-1.3.9-8.44.1, …), 87 product×package rows across 10 product lines (SUSE Linux Enterprise Module for Legacy 12, SUSE Linux Enterprise Server 11 SP1, … (10 product lines)): Fixed 83, Known Not Affected 4.

Description:

Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.

cvelogic Threat Intelligence