Integer Overflow Vulnerability in SumatraPDF Affects Windows Users
CVE-2026-107730

5.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107730?

A vulnerability exists in SumatraPDF, a popular multi-format reader for Windows, where the LitParseHeader() function in version 3.7.0.22298 utilizes signed 32-bit arithmetic in calculating section offsets. This computation can lead to an integer overflow if certain values are processed, which could result in pointer miscalculations and ultimately cause the application to terminate unexpectedly. While there is no evidence of code execution, information exposure, arbitrary read, or integrity compromise, users should exercise caution as no fix is currently available.

Affected Version(s)

sumatrapdf <= 3.7.0.22298

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.