Description
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 1.4 | Impact: 1.4Attack Vector: Local
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: Low
Affected Packages2 packages
š“Vulnerability Details
3CVEListOut-of-bounds stack array write in Xpdf 4.05 due to missing zero checkā2024-04-17 ā¶ OSVCVE-2024-3900: Out-of-bounds array write in Xpdf 4ā2024-04-17 ā¶ GHSAGHSA-4m7h-g5g8-jphw: Out-of-bounds array write in Xpdf 4ā2024-04-17 ā¶ šVendor Advisories
1Red Hatxpdf: out-of-bounds array writeā2024-04-17 ā¶