xpdf

Page content
  • Author: vmiklos
  • Vulnerable: 3.01-4
  • Unaffected: 3.02-1terminus1

A vulnerability has been reported in Xpdf, which potentially can be exploited by malicious people to compromise a user’s system. The vulnerability is caused due to an integer overflow within “StreamPredictor::StreamPredictor()” in xpdf/Stream.cc and can be exploited to cause a buffer overflow by e.g. tricking a user into opening a specially crafted PDF file in Xpdf. Successful exploitation may allow the execution of arbitrary code.

CVEs: