CVE-2024-7866

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Aug 15, 2024
Updated: Aug 19, 2024
CWE ID 674

Summary

CVE-2024-7866 is a vulnerability affecting Xpdf 4.05 and earlier versions. It arises from a PDF object loop in a pattern resource, leading to an infinite recursion and a resulting stack overflow. Malicious PDF files could exploit this weakness, potentially crashing the application or gaining unauthorized access. Users are encouraged to upgrade to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share