First published: Wed Apr 02 2025(Updated: )
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.
Credit: xpdf@xpdfreader.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf | <=4.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3154 is considered a high severity vulnerability due to its potential for causing an out-of-bounds write leading to arbitrary code execution.
To mitigate CVE-2025-3154, users should upgrade to Xpdf version 4.06 or later, which contains the necessary security patches.
CVE-2025-3154 specifically affects Xpdf versions 4.05 and earlier.
CVE-2025-3154 is classified as an out-of-bounds write vulnerability found within the Xpdf PDF rendering software.
Yes, CVE-2025-3154 can potentially allow attackers to execute arbitrary code, which could lead to data compromise.