First published: Thu Mar 20 2025(Updated: )
Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
Credit: xpdf@xpdfreader.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | <=4.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-2574 is considered high due to the potential for arbitrary code execution.
To fix CVE-2025-2574, upgrade to Xpdf version 4.06 or later which includes patches for the vulnerability.
CVE-2025-2574 affects Xpdf versions up to and including 4.05.
CVE-2025-2574 is caused by an out-of-bounds array write due to incorrect integer overflow checking in the PostScript function interpreter code.
The potential consequences of CVE-2025-2574 include security breaches that could allow attackers to execute arbitrary code on affected systems.