CVE-2024-7867
Xpdfreader
CVE-2024-7867: Integer overflow and divide-by-zero vulnerability in Xpdf. CVE-2024-7867 exposes Xpdf to potential denial-of-service attacks. In Xpdf version 4.05 and earlier, excessively large coordinates within a page box can trigger an integer overflow leading to a divide-by-zero error. This vulnerability could allow attackers to craft malicious PDF files that crash the application, disrupting services and potentially leading to further exploitation. While the CVSS score is 6.2, the SOCRadar Vulnerability Risk Score (SVRS) is 58, indicating a moderate risk level that warrants monitoring. Although not critical (SVRS above 80), the potential for denial-of-service makes addressing this vulnerability important for maintaining system stability. The risk stems from the lack of proper input validation when processing PDF files. It's significant because Xpdf is a widely used PDF rendering library, making many applications potentially vulnerable.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.