PT-2018-3976 · Xpdf+2 · Xpdf+2

·

CVE-2018-16369

·

Publicado

2018-09-02

·

Atualizado

2025-05-20

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xpdf version 4.00
Description The issue is related to errors in the code of the Xpdf software, specifically in the XRef::fetch function in XRef.cc. It allows remote attackers to cause a denial of service, which is a stack consumption, via a crafted PDF file. This is related to the AcroForm::scanField function.
Recommendations For Xpdf version 4.00, consider disabling the XRef::fetch function as a temporary workaround until a patch is available. Restrict access to the AcroForm::scanField function to minimize the risk of exploitation. Avoid using the Xpdf software to process untrusted PDF files until the issue is resolved.

Exploit

Correção

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-10474
ALT-PU-2024-10804
ALT-PU-2024-7465
BDU:2024-01225
CVE-2018-16369

Produtos afetados

Alt Linux
Debian
Xpdf