CVE-2018-16369: Medium severity xpdf vulnerability
Published Sep 3, 2018
·Updated
XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Sep 3, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16369?
CVE-2018-16369 has been classified as a denial of service vulnerability with a potential impact on availability.
2
How do I fix CVE-2018-16369?
To mitigate CVE-2018-16369, users should update to the latest version of Xpdf that addresses this vulnerability.
3
What kind of attack does CVE-2018-16369 involve?
CVE-2018-16369 involves a denial of service attack caused by stack consumption from a crafted PDF file.
4
Which software is affected by CVE-2018-16369?
CVE-2018-16369 affects Xpdf version 4.00.
5
Can CVE-2018-16369 be exploited remotely?
Yes, CVE-2018-16369 can be exploited remotely by delivering a specially crafted PDF file to the target.