CVE-2023-2662: Divide-by-zero in Xpdf 4.04 due to bad color space object
Published May 11, 2023
·Updated
In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
Affected Software
1 affected component
Xpdfreader Xpdf<=4.04
Event History
May 11, 2023
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Xpdf vulnerability?
The vulnerability ID for this Xpdf vulnerability is CVE-2023-2662.
2
What is the affected software and version for this vulnerability?
The affected software and version for this vulnerability is Xpdf 4.04 (and earlier).
3
What is the severity rating for this vulnerability?
The severity rating for this vulnerability is medium with a value of 5.5.
4
How can a bad color space object in the input PDF file cause a divide-by-zero?
A bad color space object in the input PDF file can cause a divide-by-zero due to a vulnerability in Xpdf 4.04 (and earlier).
5
Is there a fix available for this vulnerability?
It is recommended to update to a version of Xpdf that is not affected by this vulnerability.