Security Advisory

CVE-2022-30524

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-05-09 18:00:09
Last updated 2024-08-03 06:48:36
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.