Xpdf
cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*
- <= 4.05
A stack overflow vulnerability due to infinite recursion has been identified in Xpdf versions through 4.05. This issue arises from a PDF object loop in a CMap, triggered by the 'UseCMap' entry, causing the application to enter an endless loop and eventually overflow the stack.
Exploitation of this vulnerability causes a stack overflow, which can lead to arbitrary code execution or a denial-of-service condition by crashing the application.
Users can upgrade to Xpdf version 4.06, where this vulnerability will be fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.