Global Buffer Overflow in XPDF Software by JH Cloos
CVE-2022-38236
7.8HIGH
What is CVE-2022-38236?
A global buffer overflow vulnerability was identified in the XPDF product due to an improper handling of input within the Lexer::getObj(Object*) function at /xpdf/Lexer.cc. This flaw allows for potential unauthorized access and could lead to exploitation if an attacker crafts a specific input that exceeds the allocated memory limit.
