PT-2019-19728 · Foolabs+1 · Xpdf+1
Loginsoft
·
Publicado
2019-03-06
·
Atualizado
2024-08-08
·
CVE-2019-9587
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xpdf version 4.01
Description
A stack consumption issue exists in the
md5Round1() function located in Decrypt.cc. This issue can be triggered by sending a crafted pdf file to the pdfimages binary, allowing an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. The issue is related to Catalog::countPageTree.Recommendations
For Xpdf version 4.01, consider disabling the
md5Round1() function as a temporary workaround until a patch is available. Restrict access to the pdfimages binary to minimize the risk of exploitation. Avoid using crafted pdf files that may trigger the stack consumption issue until the issue is resolved.Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Xpdf