PT-2022-20158 · Xpdf+1 · Xpdf+1

H00K1998

·

Published

2022-05-09

·

Updated

2024-08-08

·

CVE-2022-30524

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xpdf version 4.0.4
Description The issue is caused by an invalid memory access in the TextLine class in TextOutputDev.cc. This occurs because the text extractor mishandles characters at large y coordinates. It can be triggered by sending a crafted pdf file to the pdftotext binary, allowing a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Recommendations For Xpdf version 4.0.4, consider avoiding the use of the pdftotext binary with untrusted pdf files until a patch is available. As a temporary workaround, restrict access to the TextOutputDev.cc module to minimize the risk of exploitation.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10474
ALT-PU-2024-10804
ALT-PU-2024-7465
CVE-2022-30524
MGASA-2024-0035

Affected Products

Alt Linux
Xpdf