PT-2022-16535 · Itext · Itext

Han0Nly

+5

·

Published

2022-02-01

·

Updated

2023-03-25

·

CVE-2022-24197

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iText version 7.1.17
Description A stack-based buffer overflow was discovered in the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Recommendations For iText version 7.1.17, consider disabling the ByteBuffer.append component until a patch is available to prevent potential Denial of Service (DoS) attacks.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-24197
GHSA-C32G-2MGR-CFQ7

Affected Products

Itext