Vulnerabilities > CVE-2024-7868 - Use of Uninitialized Resource vulnerability in Xpdfreader Xpdf

047910
CVSS 8.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
xpdfreader
CWE-908

Summary

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.

Common Weakness Enumeration (CWE)