CVE-2025-2574: Out-of-bounds array write in Xpdf 4.05 due to incorrect integer overflow checking
Published Mar 20, 2025
·Updated
Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
Affected Software
1 affected component
xpdf Xpdf<=4.05
Event History
Mar 20, 2025
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-2574?
The severity of CVE-2025-2574 is considered high due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-2574?
To fix CVE-2025-2574, upgrade to Xpdf version 4.06 or later which includes patches for the vulnerability.
3
What systems are affected by CVE-2025-2574?
CVE-2025-2574 affects Xpdf versions up to and including 4.05.
4
What causes CVE-2025-2574?
CVE-2025-2574 is caused by an out-of-bounds array write due to incorrect integer overflow checking in the PostScript function interpreter code.
5
What are the potential consequences of CVE-2025-2574?
The potential consequences of CVE-2025-2574 include security breaches that could allow attackers to execute arbitrary code on affected systems.