Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Blbi

#34871of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2020-17318
7.5
2020-12-26
Xpdf · Xpdf · CVE-2020-35376
**Name of the Vulnerable Software and Affected Versions** Xpdf version 4.02 **Description** The issue is related to an incorrect subroutine reference in a Type 1C font charstring. This is connected to the `FoFiType1C::getOp()` function, which can lead to stack consumption. **Recommendations** For Xpdf version 4.02, consider restricting the use of Type 1C font charstrings until a patch is available. As a temporary workaround, consider disabling the `FoFiType1C::getOp()` function to minimize the risk of exploitation.