{"id":"UBUNTU-CVE-2023-26930","details":"** DISPUTED ** Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”","modified":"2023-04-26T19:15:00Z","published":"2023-04-26T19:15:00Z","withdrawn":"2025-06-23T15:56:50Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-26930"},{"type":"REPORT","url":"https://github.com/huanglei3/xpdf_aborted"},{"type":"REPORT","url":"https://gist.github.com/huanglei3/10e2a9bd07a109995b20ade306612a34"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-26930"}],"affected":[{"package":{"name":"ipe","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/ipe"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.1.4-2.1","7.1.8-1","7.1.10-1","7.1.10-1.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26930.json"}},{"package":{"name":"ipe","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/ipe"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.7-2","7.2.7-3"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26930.json"}},{"package":{"name":"ipe","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ipe"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.9-1","7.2.13-2","7.2.13-2build1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26930.json"}},{"package":{"name":"ipe","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ipe"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.23+dfsg1-2","7.2.24+dfsg1-1","7.2.24+dfsg1-1build1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26930.json"}},{"package":{"name":"ipe","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ipe"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.2.27+dfsg1-2","7.2.28-2","7.2.28-2.1build2","7.2.28-2.1build3","7.2.28-2.1build4"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26930.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}