Vulnerabilities > CVE-2018-7174 - Infinite Loop vulnerability in Xpdfreader Xpdf 4.00

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
xpdfreader
CWE-835

Summary

An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.

Vulnerable Configurations

Part Description Count
Application
Xpdfreader
1