| Name | CVE-2007-5393 |
| Description | Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-1408-1, DSA-1480-1, DSA-1509-1, DSA-1537-1, DTSA-85-1, DTSA-86-1 |
| Debian Bugs | 450628, 450629, 450630, 450631 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| cups (PTS) | bookworm, bookworm (security) | 2.4.2-3+deb12u9 | fixed |
| trixie | 2.4.10-3+deb13u2 | fixed |
| trixie (security) | 2.4.10-3+deb13u1 | fixed |
| forky, sid | 2.4.18-1 | fixed |
| libextractor (PTS) | bookworm | 1:1.11-7 | fixed |
| trixie | 1:1.13-8 | fixed |
| forky, sid | 1:1.19-2 | fixed |
| poppler (PTS) | bookworm | 22.12.0-2+deb12u2 | fixed |
| bookworm (security) | 22.12.0-2+deb12u3 | fixed |
| trixie | 25.03.0-5+deb13u4 | fixed |
| trixie (security) | 25.03.0-5+deb13u3 | fixed |
| forky, sid | 26.07.0-2 | fixed |
| xpdf (PTS) | bookworm | 3.04+git20220601-1 | fixed |
| trixie | 3.04+git20250304-1 | fixed |
| forky, sid | 3.04+git20260802-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
pdftex links to poppler since 3.0-12, thus marking as fixed
- cupsys <not-affected> (we use xpdf-utils in sarge and poppler-utils since etch to not embedd this code)
cups uses xpdf-utils and poppler-utils
libextractor uses internal pdf decoder since 0.5.12-1, thus marking as fixed