CVE-2024-7867: Integer overflow and divide-by-zero in Xpdf 4.05 due to bogus page box coordinates
Published Aug 15, 2024
·Updated
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
Affected Software
1 affected component
Xpdfreader Xpdf<=4.05
Event History
Aug 15, 2024
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7867?
CVE-2024-7867 is rated as a critical vulnerability due to the potential for integer overflow and divide-by-zero errors.
2
How do I mitigate CVE-2024-7867?
To mitigate CVE-2024-7867, it is recommended to upgrade to the latest version of Xpdf beyond 4.05.
3
What types of software are affected by CVE-2024-7867?
CVE-2024-7867 affects Xpdf versions up to and including 4.05.
4
Can CVE-2024-7867 lead to system crashes?
Yes, CVE-2024-7867 can potentially cause system crashes due to the divide-by-zero error.
5
Is there a workaround for CVE-2024-7867?
Currently, the best course of action is to update to a fixed version, as there are no known workarounds for CVE-2024-7867.