Resource exhaustion in xpdf - CVE-2022-41844
Published: March 24, 2023 / Updated: March 24, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Slackware Linux
xpdf
app-text/xpdf
How to mitigate CVE-2022-41844
app-text/xpdf - update to 4.05