PT-2019-19910 · Xpdf · Xpdf

Publicado

2019-03-19

·

Atualizado

2021-07-21

·

CVE-2019-9877

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xpdf version 4.01
Description The issue is related to an invalid memory access in the TextPage::findGaps() function, located in TextOutputDev.c. This can be triggered by sending a crafted pdf file to the pdftops binary, potentially allowing an attacker to cause a Denial of Service (Segmentation fault) or have other unspecified impacts.
Recommendations For Xpdf version 4.01, consider disabling the TextPage::findGaps() function as a temporary workaround until a patch is available. Restrict access to the pdftops binary to minimize the risk of exploitation. Avoid using crafted pdf files with the affected binary until the issue is resolved.

Exploit

Correção

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9877

Produtos afetados

Xpdf