CVE-2018-18651: Medium severity xpdf vulnerability
Published Oct 25, 2018
·Updated
An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by large loop) via a specific pdf file, as demonstrated by pdftohtml. This is mainly caused by a large number after the /Count field in the file.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Oct 25, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-18651.
2
What software is affected by this vulnerability?
The Xpdf version 4.00 is affected by this vulnerability.
3
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium with a value of 5.5.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by launching a denial of service attack by causing a hang through a specific PDF file.
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. Please refer to the software vendor's website or support channels for the patch or updated version.