CVE-2018-7454: Null Pointer Dereference
Published Feb 24, 2018
·Updated
A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
Affected Software
1 affected component
Xpdfreader Xpdf=4.00
Event History
Feb 24, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7454?
The severity of CVE-2018-7454 is classified as high due to its potential to cause a denial of service.
2
How do I fix CVE-2018-7454?
To fix CVE-2018-7454, update to a later version of Xpdf that addresses the NULL pointer dereference issue.
3
What type of vulnerability is CVE-2018-7454?
CVE-2018-7454 is a NULL pointer dereference vulnerability that can lead to application crashes.
4
What are the potential impacts of CVE-2018-7454?
The potential impacts of CVE-2018-7454 include denial of service when processing malicious PDF files.
5
Which versions of Xpdf are affected by CVE-2018-7454?
CVE-2018-7454 specifically affects Xpdf version 4.00.