LOW
Out-of-bounds array write in Xpdf 4.05 due to missing object type check
Published May 15, 2024
2.1
LOWCVSS 4.0
EPSS 0.17%
Description
Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
Affected products
-
- Version 0StatusaffectedConstraints<=4.05
- Version
- ≤ 4.05
-
- Version 0StatusaffectedConstraints<=4.05
- Version
Red Hat Enterprise Linux 10
xpdf
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | xpdf | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2024-4976 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2280759 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44533 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-4976
- https://www.cve.org/CVERecord?id=CVE-2024-4976
- https://www.xpdfreader.com/security-bug/CVE-2024-4976.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-4976 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280759 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44533 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-4976 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-4976 | ||
| https://www.xpdfreader.com/security-bug/CVE-2024-4976.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GandC
Published May 15, 2024
Updated Aug 1, 2024
Reserved May 15, 2024
Link CVE-2024-4976
CISA Vulnrichment
Updated May 16, 2024
ENISA EUVD
EUVD-2024-44533 Assigner GandC
Published May 15, 2024
Updated Aug 1, 2024
Exploited since n/a
Link EUVD-2024-44533