Back

MEDIUM

Out-of-bounds array access due to negative object numbers in indirect references in Xpdf 4.05

Published Mar 26, 2024

Description

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.

Affected products

Remediation

Red Hat statement

Red Hat rates this as a low impact vulnerability as this demands local access and this is usually a single user activity that may not impact the whole server.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GandC
Published Mar 26, 2024
Updated Aug 6, 2024
Reserved Mar 26, 2024
CISA Vulnrichment
Updated Aug 6, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 26, 2024
ENISA EUVD
Assigner GandC
Published Mar 26, 2024
Updated Aug 6, 2024
Exploited since n/a
EUVD-2024-27911