CVE-2024-2971
Publication date 26 March 2024
Last updated 11 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| xpdf | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored end of ESM support, was needs-triage | |
| ipe | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored end of ESM support, was needs-triage |
Notes
mdeslaur
In trusty to bionic, xpdf is built with poppler as the backend library, so most xpdf issues don't apply to it. In jammy and later, the xpdf package is actually xpopple, a fork that also builds against poppler.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
2.9 · Low
Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L