CVE-2018-18456
18.10.2018, 06:29
The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xpdfreader | xpdf | 4.00 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xpdf |
| ||||||||||||||||||||||||||||||||||||||
| ipe |
| ||||||||||||||||||||||||||||||||||||||
| libextractor |
| ||||||||||||||||||||||||||||||||||||||
| poppler |
|
openSUSE / SLES Releases
openSUSE Product | |||||||
|---|---|---|---|---|---|---|---|
| libpoppler-glib8 |
| ||||||
| libpoppler-qt4-4 |
| ||||||
| libpoppler60 |
| ||||||
| poppler-tools |
|
Common Weakness Enumeration