xpdf and kpdf do not properly validate the loca table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a broken loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kpdf | Kde | * | * |
Xpdf | Xpdf | 3.0 (including) | 3.0 (including) |
Xpdf | Xpdf | 3.0_pl2 (including) | 3.0_pl2 (including) |
Xpdf | Xpdf | 3.0_pl3 (including) | 3.0_pl3 (including) |