First published: Thu Feb 15 2018(Updated: )
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | =4.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7175 has a severity rating of medium due to its potential to cause denial of service.
To fix CVE-2018-7175, upgrade to a newer version of Xpdf that addresses this vulnerability.
CVE-2018-7175 allows attackers to create a denial of service condition by exploiting a NULL pointer dereference.
Xpdf version 4.00 is specifically affected by CVE-2018-7175.
The main issue in CVE-2018-7175 is a NULL pointer dereference in the readCodestream function when processing JPX images.