Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v7 - Exploits Update (Fri Sep 21 2007)

Xpdf-libpoppler StreamPredictor Exploit

Exploits/Client Side  [Linux]




• Fri Sep 21 2007
This module exploits a integer overflow vulnerability in the xpdf and libpoppler software included in most linux distributions. The vulnerability is caused by a integer overflow in the predictor calculation, which causes a buffer overflow in the stack of the StreamPredictor::getNextLine() function. The exploit is triggered when an unsuspecting user opens a specially crafted file distributed via an email.

Exploits Vulnerabiltiy: CVE-2007-3387



< Back to Product Updates