PT-2025-3066 · Cpdf · Cpdf

Johnwhitington

·

Published

2025-01-08

·

Updated

2025-01-08

·

CVE-2024-54731

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions cpdf versions 2.8 and earlier
Description The issue allows stack consumption via a crafted PDF document. This can be achieved through a manipulated PDF document.
Recommendations For versions 2.8 and earlier, consider updating to a version that contains a fix for this issue, as no specific mitigation measures are provided for these versions. As a temporary workaround, consider restricting the processing of crafted PDF documents until a patch is available.

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2024-54731

Affected Products

Cpdf