MEDIUM
Stack overflow in Xpdf 4.05 due to object loop in PDF object stream
Published Apr 2, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.29%
Description
In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.
Affected products
-
Affected
- ≥ 0, ≤ 4.05
- ≤ 4.05
-
Affected
- ≥ 0, ≤ 4.05
Red Hat Enterprise Linux 10
xpdf
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | xpdf | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2024-3247 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2272851 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31839 Advisory
- https://forum.xpdfreader.com/viewtopic.php?t=43597 ExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-3247
- https://www.cve.org/CVERecord?id=CVE-2024-3247
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-3247 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2272851 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31839 | Advisory | |
| https://forum.xpdfreader.com/viewtopic.php?t=43597 | ExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-3247 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-3247 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GandC
Published Apr 2, 2024
Updated Aug 1, 2024
Reserved Apr 2, 2024
Link CVE-2024-3247
CISA Vulnrichment
Updated Apr 3, 2024
GitHub
No data