PT-2022-20309 · Xpdf+1 · Xpdf+1

Elvadisas

·

Published

2022-05-16

·

Updated

2024-08-08

·

CVE-2022-30775

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions xpdf version 4.04
Description The issue arises when xpdf allocates excessive memory in response to crafted input. This can be triggered by sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE CXX COMPILER=afl-clang-fast++ option.
Recommendations For xpdf version 4.04, as a temporary workaround, consider restricting the use of the pdftoppm binary until a patch is available. Additionally, avoid using the DCMAKE CXX COMPILER=afl-clang-fast++ option to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10474
ALT-PU-2024-10804
ALT-PU-2024-7465
CVE-2022-30775
MGASA-2024-0035

Affected Products

Alt Linux
Xpdf