CVE-2024-7866
Xpdfreader
CVE-2024-7866: A stack overflow vulnerability exists in Xpdf versions 4.05 and earlier. This flaw stems from a PDF object loop within a pattern resource, leading to infinite recursion. Triggering this vulnerability causes the application to repeatedly call itself, consuming memory until a stack overflow occurs.
The SVRS score of 54 indicates a moderate risk, requiring monitoring and potential patching depending on your organization's specific use of Xpdf. While the CVSS score of 5.5 also suggests a medium severity, the SVRS considers real-world threat intelligence, including exploit availability. Attackers can exploit this vulnerability by crafting malicious PDF files, potentially causing denial of service. Organizations relying on Xpdf for PDF processing should assess their exposure and consider upgrading to a patched version.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.