Xpdf Out-of-Bounds Write Vulnerability in ICCBased Color Spaces

Vulnerability

A vulnerability allowing out-of-bounds array writes has been identified in Xpdf versions through 4.06. This issue arises from improper validation of the 'N' field in ICCBased color spaces, leading to potential memory corruption.

Impact

Exploitation of this vulnerability could result in memory corruption, which may be leveraged to execute arbitrary code or cause a denial-of-service condition.

Remediation

Users can upgrade to Xpdf version 4.07 to address this vulnerability.

Added: Mar 18, 2026, 10:20 PM
Updated: Mar 18, 2026, 10:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
1.3
exploitability
4.2
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.