CORE IMPACT v7 - Exploits Update (Fri Sep 21 2007)
Xpdf-libpoppler StreamPredictor Exploit
Exploits/Client Side [Linux]
Fri Sep 21 2007
This module exploits a integer overflow vulnerability in the xpdf and libpoppler software included in most linux distributions. The vulnerability is caused by a integer overflow in the predictor calculation, which causes a buffer overflow in the stack of the StreamPredictor::getNextLine() function. The exploit is triggered when an unsuspecting user opens a specially crafted file distributed via an email.
Exploits Vulnerabiltiy: CVE-2007-3387











