CVE-2025-3154: Out-of-bounds array write due to invalid VerticesPerRow in Xpdf 4.05
Published Apr 2, 2025
·Updated
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.
Affected Software
1 affected component
xpdf Xpdf<=4.05
Event History
Apr 2, 2025
CVE Published
via MITRE·10:18 PM
Data Sourced
via MITRE·10:18 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3154?
CVE-2025-3154 is considered a high severity vulnerability due to its potential for causing an out-of-bounds write leading to arbitrary code execution.
2
How do I fix CVE-2025-3154?
To mitigate CVE-2025-3154, users should upgrade to Xpdf version 4.06 or later, which contains the necessary security patches.
3
What software is affected by CVE-2025-3154?
CVE-2025-3154 specifically affects Xpdf versions 4.05 and earlier.
4
What type of vulnerability is CVE-2025-3154?
CVE-2025-3154 is classified as an out-of-bounds write vulnerability found within the Xpdf PDF rendering software.
5
Can CVE-2025-3154 lead to data compromise?
Yes, CVE-2025-3154 can potentially allow attackers to execute arbitrary code, which could lead to data compromise.