Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2024-4976
HistoryMay 15, 2024 - 9:15 p.m.

CVE-2024-4976

2024-05-1521:15:09
Alpine Linux Development Team
security.alpinelinux.org
1
cve-2024-4976
xpdf
out-of-bounds
array write
acroform
field reference
unix

CVSS4

2.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:L

AI Score

7.3

Confidence

Low

Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.

OSVersionArchitecturePackageVersionFilename
Alpineedge-communitynoarchxpdf= 4.05-r0UNKNOWN
Alpine3.20-communitynoarchxpdf= 4.05-r0UNKNOWN

CVSS4

2.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:L

AI Score

7.3

Confidence

Low

Related for ALPINE:CVE-2024-4976