Vulnerabilities > CVE-2018-7453 - Infinite Loop vulnerability in Xpdfreader Xpdf 4.00

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL

Summary

Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.

Vulnerable Configurations

Part Description Count
Application
Xpdfreader
1