Vulnerability Description
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xpdfreader | Xpdf | 4.04 |
Related Weaknesses (CWE)
References
- http://www.xpdfreader.com/download.htmlPatchVendor Advisory
- https://forum.xpdfreader.com/viewtopic.php?f=1&t=42340&p=43928&hilit=gfseek#p439ExploitIssue TrackingVendor Advisory
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=42308&p=43844&hilit=XRef%3A%3AfIssue TrackingVendor Advisory
- http://www.xpdfreader.com/download.htmlPatchVendor Advisory
- https://forum.xpdfreader.com/viewtopic.php?f=1&t=42340&p=43928&hilit=gfseek#p439ExploitIssue TrackingVendor Advisory
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=42308&p=43844&hilit=XRef%3A%3AfIssue TrackingVendor Advisory
FAQ
What is CVE-2022-41844?
CVE-2022-41844 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
How severe is CVE-2022-41844?
CVE-2022-41844 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41844?
Check the references section above for vendor advisories and patch information. Affected products include: Xpdfreader Xpdf.