CVE-2024-4976: Out-of-bounds array write in Xpdf 4.05 due to missing object type check
Published May 15, 2024
·Updated
Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
Affected Software
2 affected components
xpdf Xpdf<=4.05
Xpdfreader Xpdf<=4.05
Event History
May 15, 2024
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionWeakness
Mar 30, 57258
Event
via FIRST·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-4976?
CVE-2024-4976 has been classified as a critical severity vulnerability due to its potential for exploitation.
2
How do I fix CVE-2024-4976?
To fix CVE-2024-4976, update Xpdf to version 4.06 or later, where the issue has been patched.
3
What products are affected by CVE-2024-4976?
CVE-2024-4976 affects all versions of Xpdf up to and including 4.05.
4
What type of vulnerability is CVE-2024-4976?
CVE-2024-4976 is categorized as an out-of-bounds array write vulnerability.
5
What causes the CVE-2024-4976 vulnerability?
The CVE-2024-4976 vulnerability is caused by a missing object type check in AcroForm field references within Xpdf.