CVE-2023-2664: Stack overflow in Xpdf 4.04 due to object loop in PDF embedded file tree
Published May 11, 2023
·Updated
In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.
Affected Software
1 affected component
Xpdfreader Xpdf<=4.04
Event History
May 11, 2023
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Xpdf vulnerability?
The vulnerability ID for this Xpdf vulnerability is CVE-2023-2664.
2
What is the severity rating for this Xpdf vulnerability?
The severity rating for this Xpdf vulnerability is medium with a CVSS score of 5.5.
3
What is the affected software for this Xpdf vulnerability?
The affected software for this Xpdf vulnerability is Xpdfreader Xpdf version 4.04 and earlier.
4
What is the impact of this Xpdf vulnerability?
This Xpdf vulnerability can lead to infinite recursion and a stack overflow.
5
Is there a fix available for this Xpdf vulnerability?
Yes, updating to a version later than 4.04 will fix this Xpdf vulnerability.