Description
Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
Published: 2026-09-03
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Xpdf version 4.06 and earlier has a division‑by‑zero flaw triggered when a Type 3 font glyph has zero height. The flaw causes the viewer to crash, resulting in a denial of service. No compromise of confidentiality or integrity is reported, and the attack does not allow arbitrary code execution.

Affected Systems

Xpdf for all operating systems, versions 4.06 and prior are affected. The flaw exists in the core rendering engine that processes Type 3 fonts.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity. No EPSS data or KEV listing is available, suggesting a low probability of exploitation. The most likely attack vector is a malicious PDF containing a zero‑height glyph; the victim must open the file for the crash to occur. No additional privileges or network access are required.

Generated by OpenCVE AI on September 3, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Xpdf website for a newer release that addresses this flaw and upgrade to that version.
  • If no patch is available, configure Xpdf to disable support for Type 3 fonts or use a sanitizing tool to strip such fonts from PDFs before opening.
  • After applying changes, monitor the application for crashes and apply any future vendor updates promptly.

Generated by OpenCVE AI on September 3, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Xpdf
Xpdf xpdf
Vendors & Products Xpdf
Xpdf xpdf

Thu, 03 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
Title Divide-by-zero in Xpdf 4.06 due to zero-height Type 3 glyph
Weaknesses CWE-369
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GandC

Published:

Updated: 2026-09-03T20:25:18.792Z

Reserved: 2026-09-03T20:10:21.048Z

Link: CVE-2026-85458

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T21:17:24.170

Modified: 2026-09-03T21:17:24.170

Link: CVE-2026-85458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:45:10Z

Weaknesses