CVE-2024-3900: Out-of-bounds stack array write in Xpdf 4.05 due to missing zero check
Published Apr 17, 2024
·Updated
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
Affected Software
2 affected components
xpdf Xpdf<4.05
Xpdfreader Xpdf<=4.05
Event History
Apr 17, 2024
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 21, 57052
Event
via NVD·02:40 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-3900?
CVE-2024-3900 has a high severity rating due to the potential for remote code execution from an out-of-bounds array write.
2
How do I fix CVE-2024-3900?
To fix CVE-2024-3900, upgrade Xpdf to version 4.06 or later where the vulnerability is addressed.
3
Which versions of Xpdf are affected by CVE-2024-3900?
Xpdf versions 4.05 and earlier are affected by CVE-2024-3900.
4
What type of vulnerability is CVE-2024-3900?
CVE-2024-3900 is an out-of-bounds array write vulnerability.
5
What can be exploited through CVE-2024-3900?
CVE-2024-3900 can be exploited through specially crafted PDF files containing long Unicode sequences.