Short Name |
HTTP:STC:ADOBE:PDF-DRAWIMG |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Xpdf Splash DrawImage Integer Overflow |
Release Date |
2010/10/14 |
Update Number |
1792 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
An integer overflow vulnerability exists in Xpdf. The vulnerability is due to lack of input validation when handling images within PDF documents. A remote attacker can exploit this vulnerability by enticing the target user to open a specially crafted PDF file with the affected application. Successful exploitation would allow for arbitrary code injection and execution with the privileges of the currently logged in user. In such a case, the behaviour of the target is dependent on the intention of the malicious code. In the case where code execution is not successful, the application could terminate abnormally.
Xpdf is prone to multiple integer-overflow vulnerabilities. Exploiting these issues may allow remote attackers to execute arbitrary code in the context of an affected application or cause denial-of-service conditions.