Xpdf Vulnerability Allows Denial of Service
Summary
CERT-Bund has issued a security advisory regarding a denial-of-service vulnerability in the Xpdf PDF viewer. The vulnerability affects versions of Xpdf on Linux, UNIX, and Windows systems. The advisory provides information on the vulnerability and mitigation, noting a CVSS base score of 2.9.
What changed
CERT-Bund has published a security advisory (WID-SEC-2026-0786) detailing a denial-of-service vulnerability in the Xpdf PDF viewer, specifically affecting version 4.06. The vulnerability can be exploited by a local attacker and has a CVSS base score of 2.9. The advisory applies to Xpdf installations on Linux, UNIX, and Windows operating systems.
While this is a security advisory and not a regulatory mandate, organizations using Xpdf should be aware of this vulnerability. Users are advised to check for updated versions or apply any available mitigations once released by the vendor to prevent potential denial-of-service disruptions. The advisory does not specify a compliance deadline, but prompt review of security updates is recommended.
What to do next
- Review Xpdf installations for version 4.06.
- Monitor for vendor-released patches or mitigation guidance.
Source document (simplified)
[WID-SEC-2026-0786] xpdf: Schwachstelle ermöglicht Denial of Service CVSS Base Score 2.9 (niedrig) CVSS Temporal Score 2.7 (niedrig) Remoteangriff nein Datum 18.03.2026 Stand 19.03.2026 Mitigation nein
Betroffene Systeme
Betriebssystem
- Linux
- UNIX
- Windows
Produktbeschreibung
Mit Xpdf können PDF-Dokumente betrachtet werden. Dieser PDF-Betrachter ist zudem auch für Microsoft Windows verfügbar.
Produkte
18.03.2026
- Open Source xpdf 4.06
Angriff
Angriff
Ein lokaler Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.