CVE-2019-12360
27.05.2019, 23:29
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.Enginsight
Vendor | Product | Version |
---|---|---|
glyphandcog | xpdfreader | 4.01.01 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
emscripten |
| ||||||||||||||||||||||||||||||
ipe |
| ||||||||||||||||||||||||||||||
libextractor |
| ||||||||||||||||||||||||||||||
poppler |
| ||||||||||||||||||||||||||||||
texlive-bin |
| ||||||||||||||||||||||||||||||
utopia-documents |
| ||||||||||||||||||||||||||||||
xpdf |
|
Common Weakness Enumeration
References