Unbounded Array Write Vulnerability in Xpdf
CVE-2024-3900
5.5MEDIUM
What is CVE-2024-3900?
The vulnerability in Xpdf involves an out-of-bounds array write that can be exploited by crafting a long Unicode sequence within the ActualText. This flaw potentially allows attackers to manipulate the application’s memory, leading to unexpected behavior or crashes. Users of Xpdf Reader version 4.05 and earlier are particularly at risk, highlighting the importance of applying security updates and patches to mitigate potential exploit scenarios.
Affected Version(s)
Xpdf all 0 <= 4.05
