PT-2019-19729 · Foxtan+1 · Xpdf+1

Loginsoft

·

Published

2019-03-06

·

Updated

2024-08-08

·

CVE-2019-9588

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xpdf version 4.01
Description The issue is related to an invalid memory access in the gAtomicIncrement() function, located in GMutex.h. This can be triggered by sending a crafted pdf file to the pdftops binary, for example. The impact of this issue includes causing a Denial of Service, resulting in a Segmentation fault, and potentially having other unspecified effects.
Recommendations For Xpdf version 4.01, consider restricting access to the pdftops binary until a fix is available, and avoid processing crafted pdf files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10474
ALT-PU-2024-10804
ALT-PU-2024-7465
CVE-2019-9588

Affected Products

Alt Linux
Xpdf