CVE-2018-18455: Medium severity xpdf vulnerability
Published Oct 18, 2018
·Updated
The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Oct 18, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-18455.
2
What is the severity rating of CVE-2018-18455?
CVE-2018-18455 has a severity rating of 5.5, which is considered medium.
3
How does CVE-2018-18455 affect Xpdf?
CVE-2018-18455 affects Xpdf version 4.00.
4
How can an attacker exploit CVE-2018-18455?
An attacker can exploit CVE-2018-18455 by using a crafted PDF file, as demonstrated by pdftoppm.
5
Is there a fix available for CVE-2018-18455?
To mitigate CVE-2018-18455, it is recommended to update Xpdf to a version that is not affected by this vulnerability.