CVE-2024-42358
Linux Debian vulnerability analysis and mitigation

Overview

PDFio, a simple C library for reading and writing PDF files, contains a denial of service (DOS) vulnerability in its TTF parser identified as CVE-2024-42358. The vulnerability was discovered and disclosed on August 6, 2024, affecting all versions up to 1.3.0. When processing maliciously crafted TTF files, the parser can be forced to utilize 100% of memory and enter an infinite loop, potentially leading to a heap-buffer-overflow condition (GitHub Advisory, NVD).

Technical details

The vulnerability occurs in the TTF parser's read_cmap function, specifically triggered by manipulating the nGroups value. The issue manifests when a maliciously crafted value is extracted from the file, causing the program to enter an infinite loop and consume excessive memory. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (MEDIUM) by NIST with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, while GitHub assessed it at 6.2 (MEDIUM) with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The vulnerability can significantly impact systems that use PDFio, particularly automated systems and web servers that process PDF submissions containing TTF fonts. When exploited, the vulnerability can cause denial of service conditions by consuming 100% of system memory and entering an infinite loop. Additionally, the issue can lead to heap-buffer-overflow vulnerabilities, potentially affecting system stability and security (GitHub Advisory).

Exploitability

The vulnerability can be triggered by uploading a maliciously crafted TTF file to systems using the affected PDFio versions. The exploit requires no special privileges but does need the ability to submit files for processing. The vulnerability has been demonstrated to be reliably exploitable through specially crafted TTF files (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been addressed in PDFio version 1.3.1. All users are advised to upgrade to this version as there are no known workarounds for this vulnerability. The fix includes implementation of proper range checking in the TTF loader (NVD, GitHub Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management