PT-2018-3976 · Xpdf+2 · Xpdf+2
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Xpdf version 4.00
Description
The issue is related to errors in the code of the Xpdf software, specifically in the XRef::fetch function in XRef.cc. It allows remote attackers to cause a denial of service, which is a stack consumption, via a crafted PDF file. This is related to the AcroForm::scanField function.
Recommendations
For Xpdf version 4.00, consider disabling the XRef::fetch function as a temporary workaround until a patch is available. Restrict access to the AcroForm::scanField function to minimize the risk of exploitation. Avoid using the Xpdf software to process untrusted PDF files until the issue is resolved.
Exploit
Correção
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Xpdf