Xpdf · Xpdf · CVE-2022-43071
**Name of the Vulnerable Software and Affected Versions**
XPDF version 4.04
**Description**
A stack overflow in the `Catalog::readPageLabelTree2(Object*)` function allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
**Recommendations**
For XPDF version 4.04, as a temporary workaround, consider disabling the `Catalog::readPageLabelTree2(Object*)` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.