VDB
CVE-2023-26930
CVE-2023-26930
PUBLISHED
In xpdf existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund von mehreren Pufferüberläufen und einem unbeschriebenen Problem in den Funktionen goo/GString.cc, goo/gfile.cc, pdftotext.cc, TextOutputDev.cc, object.cc, /xpdf/Stream.cc und gmem.cc. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um einen Denial-of-Service-Zustand zu verursachen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.14% · 34.6th percentile
Risk Scores
EPSS Score
0.14%
34.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source | Open Source xpdf 4.04 |
Timeline
- Apr 26, 2023 CVE Published
- Apr 26, 2023 PoC Published
- Apr 27, 2023 EPSS Score
- Jun 3, 2023 EPSS Score
- Jul 10, 2023 EPSS Score
- Aug 16, 2023 EPSS Score
- Sep 23, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 6, 2023 EPSS Score
- Jan 12, 2024 EPSS Score
- Feb 18, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1089.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1089 advisory
- https://github.com/huanglei3/xpdf_Stack-backtracking/blob/main/gmem_copyString advisory
- https://github.com/huanglei3/xpdf_heapoverflow advisory
- https://github.com/huanglei3/xpdf_Stack-backtracking/blob/main/object_copy advisory
- https://note.youdao.com/ynoteshare/index.html?id=3e538317260c2d0a7a8af70140c63a0f&type=note&_time=1682579239360 advisory
- https://github.com/huanglei3/xpdf_Stack-backtracking/blob/main/Stack_backtracking_gstring advisory
- https://github.com/advisories/GHSA-rqfx-p88v-f7ff advisory
- https://github.com/advisories/GHSA-jw72-cmc9-886w advisory
- https://github.com/advisories/GHSA-j96r-2c7w-r3f2 advisory
- https://github.com/advisories/GHSA-mmph-h7pj-hh4p advisory
- https://github.com/advisories/GHSA-g4vj-r7jx-86jx advisory
- https://github.com/advisories/GHSA-c7xr-8x4j-9789 advisory
- https://github.com/advisories/GHSA-29j9-xmmx-g9r4 advisory