40275vdb entry
http://osvdb.org/40275 CVE-2007-6561
PDFlib 7.0.2 - Multiple Remote Buffer Overflow Vulnerabilities
Record summary
CVE-2007-6561 has a selected CVSS score of 5.7; EIP currently links 1 catalogued exploit.
Description
Multiple stack-based buffer overflows in PDFLib allow user-assisted remote attackers to execute arbitrary code via a long filename argument to the PDF_load_image function that results in an overflow in the pdc_fsearch_fopen function, and possibly other vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPDFlib 7.0.2 - Multiple Remote Buffer Overflow VulnerabilitiesExploitDB exploitby poplixNot analyzed1 file
References
828239Third-party advisory
http://secunia.com/advisories/28239 29304Third-party advisory
http://secunia.com/advisories/29304 GLSA-200803-17Vendor advisory
http://security.gentoo.org/glsa/glsa-200803-17.xml 3495Third-party advisory
http://securityreason.com/securityalert/3495 20071222 pdflib long filename multiple bufferoverflowsmailing list
http://www.securityfocus.com/archive/1/485479/100/0/threaded 27001vdb entry
http://www.securityfocus.com/bid/27001 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6561