Vulnerabilities > CVE-2024-4141 - Out-of-bounds Write vulnerability in Xpdfreader Xpdf

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
xpdfreader
CWE-787

Summary

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

Common Weakness Enumeration (CWE)