PT-2019-14933 · Xpdf · Xpdf

Dhiraj

·

Published

2019-10-01

·

Updated

2019-12-31

·

CVE-2019-17064

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xpdf version 4.02
Description The issue arises from a NULL pointer dereference in Catalog.cc due to the late initialization of Catalog.pageLabels in the Catalog constructor.
Recommendations For Xpdf version 4.02, ensure that the Catalog.pageLabels is properly initialized before use to prevent the NULL pointer dereference. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17064
MGASA-2019-0422

Affected Products

Xpdf