Input validation error in xpdf - CVE-2018-16369
Published: September 3, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml.
Affected software
Gentoo Linux
Slackware Linux
xpdf
app-text/xpdf
How to mitigate CVE-2018-16369
app-text/xpdf - update to 4.05