First published: Thu Oct 25 2018(Updated: )
An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by large loop) via a specific pdf file, as demonstrated by pdftohtml. This is mainly caused by a large number after the /Count field in the file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdfreader Xpdf | =4.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-18651.
The Xpdf version 4.00 is affected by this vulnerability.
The severity rating of this vulnerability is medium with a value of 5.5.
This vulnerability can be exploited by launching a denial of service attack by causing a hang through a specific PDF file.
Yes, a fix is available for this vulnerability. Please refer to the software vendor's website or support channels for the patch or updated version.