PT-2020-15279 · Pdfresurrect+2 · Pdfresurrect+2

Yifengchen-Cc

·

Published

2020-11-20

·

Updated

2022-06-03

·

CVE-2020-20740

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PDFResurrect versions prior to 0.20
Description The issue is caused by a lack of header validation checks, leading to a heap-buffer-overflow in the pdf get version() function. This can occur due to improper validation of PDF headers.
Recommendations For versions prior to 0.20, update to version 0.20 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pdf get version() function until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20740
DLA-2475-1
MGASA-2020-0449
USN-5282-1

Affected Products

Linuxmint
Pdfresurrect
Ubuntu