CVE-2018-7453: Medium severity Xpdfreader Xpdf vulnerability
Published Feb 24, 2018
·Updated
Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Feb 24, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7453?
CVE-2018-7453 has been classified as a denial of service vulnerability due to infinite recursion.
2
How does CVE-2018-7453 affect xpdf users?
CVE-2018-7453 can cause xpdf to crash or become unresponsive when processing a malicious PDF file.
3
How do I fix CVE-2018-7453?
To fix CVE-2018-7453, update to a version of xpdf beyond 4.00 that addresses this vulnerability.
4
What software is affected by CVE-2018-7453?
CVE-2018-7453 affects xpdf version 4.00 specifically.
5
What is the attack vector for CVE-2018-7453?
The attack vector for CVE-2018-7453 is via a specially crafted PDF file that triggers infinite recursion.