CVE-2018-7174: Medium severity Xpdfreader Xpdf vulnerability
Published Feb 15, 2018
·Updated
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Feb 15, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7174?
CVE-2018-7174 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-7174?
The recommended fix for CVE-2018-7174 is to upgrade to a version of xpdf later than 4.00.
3
What software is affected by CVE-2018-7174?
CVE-2018-7174 specifically affects xpdf version 4.00.
4
Can CVE-2018-7174 be exploited remotely?
Yes, CVE-2018-7174 can be exploited remotely through specially crafted PDF files.
5
What type of attack does CVE-2018-7174 facilitate?
CVE-2018-7174 facilitates denial of service attacks due to an infinite loop vulnerability.