CVE-2022-43071: Medium severity Xpdfreader Xpdf vulnerability
A stack overflow in the Catalog::readPageLabelTree2(Object) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43071?
CVE-2022-43071 is a vulnerability in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 that allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
How can attackers exploit CVE-2022-43071?
Attackers can exploit CVE-2022-43071 by sending a crafted PDF file to the vulnerable XPDF v4.04 application, causing it to crash and become unresponsive.
What is the severity of CVE-2022-43071?
CVE-2022-43071 has a severity score of 5.5, which is considered medium.
How can I mitigate CVE-2022-43071?
The recommended mitigation for CVE-2022-43071 is to update XPDF to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-43071?
You can find more information about CVE-2022-43071 at the following reference: [https://forum.xpdfreader.com/viewtopic.php?f=3&t=42349&p=43959#p43959]