In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.xpdfreader.com/security-bug/CVE-2024-7868.html |
History
Wed, 11 Sep 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xpdfreader
Xpdfreader xpdf |
|
CPEs | cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xpdfreader
Xpdfreader xpdf |
|
Metrics |
cvssV3_1
|
Thu, 15 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 15 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address. | |
Title | Uninitialized variable in Xpdf 4.05 due to invalid JPEG header | |
Weaknesses | CWE-908 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GandC
Published: 2024-08-15T20:22:52.873Z
Updated: 2024-08-15T20:33:39.716Z
Reserved: 2024-08-15T20:15:02.215Z
Link: CVE-2024-7868
Vulnrichment
Updated: 2024-08-15T20:33:32.787Z
NVD
Status : Analyzed
Published: 2024-08-15T21:15:18.530
Modified: 2024-09-11T12:40:01.817
Link: CVE-2024-7868
Redhat
No data.