Description
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =3.04+git20210103-3 || =3.04+git20211001-1 || =3.04+git20211021-1 || =3.04+git20220201-1 || =3.04+git20220601-1 || =3.04+git20231213-1 || =3.04+git20240118-1 || =3.04+git20240124-1 || =3.04+git20240202-1 || =3.04+git20240613-1 || =3.04+git20250103-1 || =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 12 | | =3.04+git20220601-1 || =3.04+git20231213-1 || =3.04+git20240118-1 || =3.04+git20240124-1 || =3.04+git20240202-1 || =3.04+git20240613-1 || =3.04+git20250103-1 || =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 14 | | =3.04+git20250304-1 || =3.04+git20260220-1 |
 debian 13 | | =3.04+git20250304-1 || =3.04+git20260220-1 |