CVE-2023-33802
MEDIUMSumatraPDF 3.4.6 - Denial of Service via Crafted Text File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-33802. PoCs published by CDACesec.
AI-analyzed exploit summary This repository documents a Denial of Service (DoS) vulnerability in SumatraPDF 3.4.6 32-bit, triggered by opening two large text files. The crash occurs due to a null pointer dereference in the `CrashMe` function, leading to an access violation.
Description
A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text file.
Exploits (1)
This repository documents a Denial of Service (DoS) vulnerability in SumatraPDF 3.4.6 32-bit, triggered by opening two large text files. The crash occurs due to a null pointer dereference in the `CrashMe` function, leading to an access violation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H