>> KDE Products "StreamPredictor::StreamPredictor()" Integer Overflow Vulnerability
Title : KDE Products "StreamPredictor::StreamPredictor()" Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2705 CVE ID : CVE-2007-3387
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-31
Technical Description
A vulnerability has been identified in KDE and KOffice, which could be exploited by remote attackers to cause a denial of service or compromise an affected system. This issue is caused by an integer overflow error in the "StreamPredictor::StreamPredictor()" [xpdf/Stream.cc] function when processing malformed data, which could be exploited by attackers to crash a vulnerable application or execute arbitrary code by tricking a user into opening a specially crafted PDF file.