CVE-2007-0102

Current Description

The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

Basic Data

PublishedJanuary 09, 2007
Last ModifiedJuly 29, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-20
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score6.8
SeverityMEDIUM
Exploitability Score8.6
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationApplePreview3.0.8*******

Vulnerable Software List

VendorProductVersions
Apple Preview 3.0.8

References

NameSourceURLTags
http://docs.info.apple.com/article.html?artnum=305214http://docs.info.apple.com/article.html?artnum=305214CONFIRM
31221http://osvdb.org/31221OSVDB
http://projects.info-pull.com/moab/MOAB-06-01-2007.htmlhttp://projects.info-pull.com/moab/MOAB-06-01-2007.htmlMISCExploit
24479http://secunia.com/advisories/24479SECUNIA
21910http://www.securityfocus.com/bid/21910BIDExploit Patch
1017749http://www.securitytracker.com/id?1017749SECTRACK
TA07-072Ahttp://www.us-cert.gov/cas/techalerts/TA07-072A.htmlCERTUS Government Resource
ADV-2007-0930http://www.vupen.com/english/advisories/2007/0930VUPEN
multiple-vendor-pdf-code-execution(31364)https://exchange.xforce.ibmcloud.com/vulnerabilities/31364XF