CVE-2022-27135

Severity
5.5MEDIUM
EPSS
0.2%
top 56.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateApr 26

Description

xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDxpdfreader/xpdf4.03

🔴Vulnerability Details

3
GHSA
GHSA-479v-8jg2-8fgj: xpdf 42022-04-26
OSV
CVE-2022-27135: xpdf 42022-04-25
CVEList
CVE-2022-27135: xpdf 42022-04-25

📋Vendor Advisories

1
Debian
CVE-2022-27135: xpdf - xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef...2022
CVE-2022-27135 (MEDIUM CVSS 5.5) | xpdf 4.03 has heap buffer overflow | cvebase.io