Segmentation Violation in XPDF Product by JHCLoos
CVE-2022-38233

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 August 2022

What is CVE-2022-38233?

A segmentation violation has been identified in the XPDF software, specifically within the DCTStream::readMCURow() function inStream.cc. This flaw may allow attackers to exploit the PDF processing capabilities of XPDF, leading to potential disruptions or unauthorized actions when handling specific PDF files. Users are advised to examine their XPDF versions and apply necessary updates to mitigate any risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.