First published: Wed Apr 24 2024(Updated: )
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.
Credit: xpdf@xpdfreader.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | <4.05 | |
Xpdf | <=4.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4141 is considered a high severity vulnerability due to its potential for an out-of-bounds array write.
To fix CVE-2024-4141, update Xpdf to version 4.06 or later to address the out-of-bounds write issue.
CVE-2024-4141 affects Xpdf versions up to and including 4.05.
CVE-2024-4141 is caused by a lack of proper bounds checking on an array in the handling of Type 1 fonts.
If exploited, CVE-2024-4141 may allow attackers to execute arbitrary code or cause denial of service.