CVE-2024-7866
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Aug 15, 2024
Updated: Aug 19, 2024
CWE ID 674
Summary
CVE-2024-7866 is a vulnerability affecting Xpdf 4.05 and earlier versions. It arises from a PDF object loop in a pattern resource, leading to an infinite recursion and a resulting stack overflow. Malicious PDF files could exploit this weakness, potentially crashing the application or gaining unauthorized access. Users are encouraged to upgrade to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Xpdfreader Xpdf