The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
                
            References
                    | Link | Resource | 
|---|---|
| https://forum.xpdfreader.com/viewtopic.php?f=3&t=652 | Issue Tracking Vendor Advisory | 
Configurations
                    Information
                Published : 2018-03-13 20:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-8107
Mitre link : CVE-2018-8107
JSON object : View
CWE
                
                    
                        
                        CWE-125
                        
            Out-of-bounds Read
Products Affected
                xpdfreader
- xpdf


