CVE-2022-30524
09.05.2022, 18:15
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xpdfreader | xpdf | 4.0.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ipe |
| ||||||||||||||||||||
| poppler |
| ||||||||||||||||||||
| xpdf |
|
Common Weakness Enumeration