CVE-2018-18456
SUSE Security Advisory - SUSE-SU-2023:4187-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
La función Object::isName() en Object.h (llamado desde Gfx::opSetFillColorN) en Xpdf 4.00 permite que atacantes remotos provoquen una denegación de servicio (sobrelectura de búfer basada en pila) mediante un archivo pdf manipulado, como ha sido demostrado por pdftoppm.
This update for poppler fixes the following issues. Fixed an out-of-bounds read vulnerability in the function SplashXPath:strokeAdjust. Fixed a stack-based buffer over-read via a crafted pdf file. Fixed heap-based buffer over-read) via a crafted pdf file. Fixed a stack bugger overflow in FoFiType1C:cvtGlyph.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-10-18 CVE Reserved
- 2018-10-18 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://forum.xpdfreader.com/viewtopic.php?f=3&t=41217 | Third Party Advisory | |
https://github.com/TeamSeri0us/pocs/tree/master/xpdf/2018_10_16/pdftoppm | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xpdfreader Search vendor "Xpdfreader" | Xpdf Search vendor "Xpdfreader" for product "Xpdf" | 4.00 Search vendor "Xpdfreader" for product "Xpdf" and version "4.00" | - |
Affected
|