CVE-2024-7868

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*:*

History

11 Sep 2024, 12:40

Type Values Removed Values Added
References () https://www.xpdfreader.com/security-bug/CVE-2024-7868.html - () https://www.xpdfreader.com/security-bug/CVE-2024-7868.html - Vendor Advisory
First Time Xpdfreader
Xpdfreader xpdf
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
CPE cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*:*

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) En Xpdf 4.05 (y versiones anteriores), la información de encabezado no válida en una secuencia DCT (JPEG) puede generar una variable no inicializada en el decodificador DCT. El archivo PDF de prueba de concepto provoca un error de segmentación al intentar leer desde una dirección no válida.

15 Aug 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 21:15

Updated : 2024-09-11 12:40


NVD link : CVE-2024-7868

Mitre link : CVE-2024-7868

CVE.ORG link : CVE-2024-7868


JSON object : View

Products Affected

xpdfreader

  • xpdf
CWE
CWE-908

Use of Uninitialized Resource