CVE-2018-7175: Null Pointer Dereference
Published Feb 15, 2018
·Updated
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Feb 15, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7175?
CVE-2018-7175 has a severity rating of medium due to its potential to cause denial of service.
2
How do I fix CVE-2018-7175?
To fix CVE-2018-7175, upgrade to a newer version of Xpdf that addresses this vulnerability.
3
What kind of attack does CVE-2018-7175 allow?
CVE-2018-7175 allows attackers to create a denial of service condition by exploiting a NULL pointer dereference.
4
Which version of Xpdf is affected by CVE-2018-7175?
Xpdf version 4.00 is specifically affected by CVE-2018-7175.
5
What is the main issue in CVE-2018-7175?
The main issue in CVE-2018-7175 is a NULL pointer dereference in the readCodestream function when processing JPX images.