First published: Mon Apr 25 2022(Updated: )
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdfreader Xpdf | =4.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this xpdf issue is CVE-2022-27135.
The severity of CVE-2022-27135 is medium with a CVSS score of 5.5.
The affected software is Xpdf 4.03.
CVE-2022-27135 is a heap buffer overflow vulnerability in xpdf 4.03, which allows an attacker to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.
At the time of writing, there is no known fix available for CVE-2022-27135. It is recommended to update to a patched version or apply any available mitigations provided by the vendor.