Impact
Xpdf version 4.06 and earlier has a division‑by‑zero flaw triggered when a Type 3 font glyph has zero height. The flaw causes the viewer to crash, resulting in a denial of service. No compromise of confidentiality or integrity is reported, and the attack does not allow arbitrary code execution.
Affected Systems
Xpdf for all operating systems, versions 4.06 and prior are affected. The flaw exists in the core rendering engine that processes Type 3 fonts.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity. No EPSS data or KEV listing is available, suggesting a low probability of exploitation. The most likely attack vector is a malicious PDF containing a zero‑height glyph; the victim must open the file for the crash to occur. No additional privileges or network access are required.
OpenCVE Enrichment