CVE-2018-18456: Medium severity xpdf vulnerability
Published Oct 18, 2018
·Updated
The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Oct 18, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-18456.
2
What is the severity level of CVE-2018-18456?
The severity level of CVE-2018-18456 is medium (5.5).
3
How does CVE-2018-18456 affect Xpdf 4.00?
CVE-2018-18456 affects Xpdf 4.00 by allowing remote attackers to cause a denial of service (stack-based buffer over-read) through a crafted pdf file.
4
How can the vulnerability in Xpdf 4.00 be exploited?
The vulnerability in Xpdf 4.00 can be exploited by using a specially crafted pdf file.
5
Is there a fix available for CVE-2018-18456?
Yes, there is a fix available for CVE-2018-18456. It is recommended to update to a version of Xpdf that includes the fix.