VYPR
High severity8.2NVD Advisory· Published Aug 15, 2024· Updated Jun 17, 2026

CVE-2024-7868

CVE-2024-7868

Description

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.

Affected products

3
  • Xpdf/Xpdfv53 versions
    0+ 2 more
    • (no CPE)range: 0
    • (no CPE)range: <=4.05
    • cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*:*range: <4.06

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.