PT-2024-38645 · Xpdf+1 · Xpdf+1
Kmfl
·
Published
2024-08-15
·
Updated
2025-10-06
·
CVE-2024-7868
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Xpdf versions 4.05 and earlier
Description
The issue arises from invalid header information in a DCT (JPEG) stream, leading to an uninitialized variable in the DCT decoder. This can cause a segfault when attempting to read from an invalid address. A proof-of-concept PDF file has been identified as triggering this issue.
Recommendations
For Xpdf versions 4.05 and earlier, consider updating to a newer version to mitigate the risk, as the current version contains an uninitialized variable in the DCT decoder that can lead to a segfault.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Xpdf