CVE-2023-2663: Stack overflow in Xpdf 4.04 due to object loop in PDF page label tree
Published May 11, 2023
·Updated
In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.
Affected Software
1 affected component
Xpdfreader Xpdf<=4.04
Event History
May 11, 2023
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Xpdf stack overflow vulnerability?
The vulnerability ID for the Xpdf stack overflow vulnerability is CVE-2023-2663.
2
What is the severity rating of CVE-2023-2663?
The severity rating of CVE-2023-2663 is 5.5 out of 10.
3
How does the Xpdf stack overflow vulnerability affect the software?
The Xpdf stack overflow vulnerability affects Xpdf version 4.04 and earlier.
4
How can I fix CVE-2023-2663?
To fix CVE-2023-2663, it is recommended to update Xpdf to a version later than 4.04.
5
Where can I find more information about CVE-2023-2663?
You can find more information about CVE-2023-2663 on the Xpdfreader forum: https://forum.xpdfreader.com/viewtopic.php?t=42421