CVE Vulnerabilities

CVE-2023-3436

Deadlock

Published: Jun 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Xpdf 4.04 will deadlock on a PDF object stream whose Length field is itself in another object stream.

Weakness

The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.

Affected Software

Name Vendor Start Version End Version
Xpdf Xpdfreader 4.04 (including) 4.04 (including)
Ipe Ubuntu bionic *
Ipe Ubuntu kinetic *
Ipe Ubuntu lunar *
Ipe Ubuntu mantic *
Ipe Ubuntu trusty *
Ipe Ubuntu xenial *
Xpdf Ubuntu bionic *
Xpdf Ubuntu kinetic *
Xpdf Ubuntu lunar *
Xpdf Ubuntu mantic *
Xpdf Ubuntu trusty *
Xpdf Ubuntu xenial *

References