PT-2020-15881 · Xpdf · Xpdf

Published

2020-09-03

·

Updated

2020-09-11

·

CVE-2020-24999

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xpdf version 4.0.2
Description The issue is caused by an invalid memory access in the fprintf function located in Error.cc. It can be triggered by sending a crafted PDF file to the pdftohtml binary, allowing a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Recommendations For Xpdf version 4.0.2, consider restricting access to the pdftohtml binary until a patch is available to prevent potential Denial of Service attacks. As a temporary workaround, avoid using the pdftohtml binary with untrusted PDF files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24999

Affected Products

Xpdf