First published: Thu Aug 15 2024(Updated: )
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
Credit: xpdf@xpdfreader.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | <=4.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7867 is rated as a critical vulnerability due to the potential for integer overflow and divide-by-zero errors.
To mitigate CVE-2024-7867, it is recommended to upgrade to the latest version of Xpdf beyond 4.05.
CVE-2024-7867 affects Xpdf versions up to and including 4.05.
Yes, CVE-2024-7867 can potentially cause system crashes due to the divide-by-zero error.
Currently, the best course of action is to update to a fixed version, as there are no known workarounds for CVE-2024-7867.