CVE Vulnerabilities

CVE-2018-7453

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Feb 24, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
XpdfXpdfreader4.00 (including)4.00 (including)
IpeUbuntuartful*
IpeUbuntubionic*
IpeUbuntucosmic*
IpeUbuntudisco*
IpeUbuntueoan*
IpeUbuntufocal*
IpeUbuntugroovy*
IpeUbuntuhirsute*
IpeUbuntuimpish*
IpeUbuntukinetic*
IpeUbuntulunar*
IpeUbuntumantic*
IpeUbuntuoracular*
IpeUbuntuplucky*
IpeUbuntutrusty*
IpeUbuntuxenial*
LibextractorUbuntuartful*
LibextractorUbuntucosmic*
LibextractorUbuntudisco*
LibextractorUbuntueoan*
LibextractorUbuntugroovy*
LibextractorUbuntuhirsute*
LibextractorUbuntuimpish*
LibextractorUbuntutrusty*
LibextractorUbuntuxenial*
XpdfUbuntuartful*
XpdfUbuntubionic*
XpdfUbuntucosmic*
XpdfUbuntudevel*
XpdfUbuntudisco*
XpdfUbuntueoan*
XpdfUbuntuesm-apps/bionic*
XpdfUbuntuesm-apps/jammy*
XpdfUbuntuesm-apps/noble*
XpdfUbuntuesm-apps/xenial*
XpdfUbuntuhirsute*
XpdfUbuntuimpish*
XpdfUbuntujammy*
XpdfUbuntukinetic*
XpdfUbuntulunar*
XpdfUbuntumantic*
XpdfUbuntunoble*
XpdfUbuntuoracular*
XpdfUbuntuplucky*
XpdfUbuntuquesting*
XpdfUbuntutrusty*
XpdfUbuntuxenial*

References