MEDIUM
Stack overflow in Xpdf 4.05 due to object loop in PDF resources
Published May 6, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
Affected products
-
Affected
- ≥ 0, ≤ 4.05
- ≤ 4.05
-
Affected
- ≥ 0, ≤ 4.05
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Glyphandcog | Xpdf | unknown | Affected
|
Red Hat Enterprise Linux 10
xpdf
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | xpdf | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2024-4568 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2279470 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44180 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-4568
- https://www.cve.org/CVERecord?id=CVE-2024-4568
- https://www.xpdfreader.com/security-bug/object-loops.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-4568 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2279470 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44180 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-4568 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-4568 | ||
| https://www.xpdfreader.com/security-bug/object-loops.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GandC
Published May 6, 2024
Updated Aug 1, 2024
Reserved May 6, 2024
Link CVE-2024-4568
CISA Vulnrichment
Updated May 7, 2024
GitHub
No data