3.3

CVE-2023-3436

Deadlock in Xpdf 4.04 due to PDF object stream references

Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xpdfreader ≫ Xpdf Version 4.04
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.067
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
xpdf@xpdfreader.com 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

CWE-833 Deadlock

The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.

https://forum.xpdfreader.com/viewtopic.php?t=42618
Issue Tracking