CVE-2023-3436: Deadlock in Xpdf 4.04 due to PDF object stream references
Published Jun 27, 2023
·Updated
Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.
Affected Software
1 affected component
Xpdfreader Xpdf=4.04
Event History
Jun 27, 2023
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3436.
2
What is the severity of CVE-2023-3436?
The severity of CVE-2023-3436 is low with a CVSS score of 3.3.
3
What software is affected by CVE-2023-3436?
Xpdf 4.04 is affected by CVE-2023-3436.
4
How can I fix CVE-2023-3436?
There is currently no available fix for CVE-2023-3436. It is recommended to stay updated with the latest information from the software vendor.
5
Where can I find more information about CVE-2023-3436?
You can find more information about CVE-2023-3436 at the following reference link: https://forum.xpdfreader.com/viewtopic.php?t=42618