PT-2019-13051 · None · Xpdf
Published
2019-06-24
·
Updated
2019-10-25
·
CVE-2019-12958
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Xpdf version 4.01.01
Description
A heap-based buffer over-read issue exists in the FoFiType1C::convertToType0 function, located in fofi/FoFiType1C.cc. This occurs when the function attempts to access the second privateDicts array element, despite the privateDicts array having only one allocated element.
Recommendations
For Xpdf version 4.01.01, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xpdf