CVE-2023-3436

CWE-833CWE-6675 documents5 sources
Severity
3.3LOW
EPSS
0.0%
top 95.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 27

Description

Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

ā–¶CVEListV5xpdf/xpdf4.04
ā–¶NVDxpdfreader/xpdf4.04

šŸ”“Vulnerability Details

3
CVEList
Deadlock in Xpdf 4.04 due to PDF object stream references↗2023-06-27
ā–¶
GHSA
GHSA-whpq-78mq-qcj6: Xpdf 4↗2023-06-27
ā–¶
OSV
CVE-2023-3436: Xpdf 4↗2023-06-27
ā–¶

šŸ“‹Vendor Advisories

1
Debian
CVE-2023-3436: xpdf - Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in...↗2023
ā–¶
CVE-2023-3436 (LOW CVSS 3.3) | Xpdf 4.04 will deadlock on a PDF ob | cvebase.io