Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppx8-qq3q-gfv8

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

EPSS

Процентиль: 56%
0.00337
Низкий

7.8 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

CVSS3: 7.8
nvd
почти 7 лет назад

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

CVSS3: 7.8
debian
почти 7 лет назад

There is a stack consumption issue in md5Round1() located in Decrypt.c ...

EPSS

Процентиль: 56%
0.00337
Низкий

7.8 High

CVSS3

Дефекты

CWE-400