Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-4141
HistoryApr 24, 2024 - 12:00 a.m.

CVE-2024-4141

2024-04-2400:00:00
ubuntu.com
ubuntu.com
8
xpdf type 1 font boundscheck

2.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid
character code in a Type 1 font. The root problem was a bounds check that
was being optimized away by modern compilers.

Notes

Author Note
mdeslaur In trusty to bionic, xpdf is built with poppler as the backend library, so most xpdf issues don’t apply to it. In jammy and later, the xpdf package is actually xpopple, a fork that also builds against poppler.

2.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%