Xpdf · Xpdf · CVE-2020-35376
**Name of the Vulnerable Software and Affected Versions**
Xpdf version 4.02
**Description**
The issue is related to an incorrect subroutine reference in a Type 1C font charstring. This is connected to the `FoFiType1C::getOp()` function, which can lead to stack consumption.
**Recommendations**
For Xpdf version 4.02, consider restricting the use of Type 1C font charstrings until a patch is available.
As a temporary workaround, consider disabling the `FoFiType1C::getOp()` function to minimize the risk of exploitation.