PT-2024-38645 · Xpdf+1 · Xpdf+1

Kmfl

·

Published

2024-08-15

·

Updated

2025-10-06

·

CVE-2024-7868

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xpdf versions 4.05 and earlier
Description The issue arises from invalid header information in a DCT (JPEG) stream, leading to an uninitialized variable in the DCT decoder. This can cause a segfault when attempting to read from an invalid address. A proof-of-concept PDF file has been identified as triggering this issue.
Recommendations For Xpdf versions 4.05 and earlier, consider updating to a newer version to mitigate the risk, as the current version contains an uninitialized variable in the DCT decoder that can lead to a segfault. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

AZL-47857
AZL-47871
BDU:2025-11543
CVE-2024-7868

Affected Products

Alt Linux
Xpdf