Out-of-bounds read in xpdf - CVE-2019-13283

 

Out-of-bounds read in xpdf - CVE-2019-13283

Published: July 29, 2019


Vulnerability identifier: #VU19543
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13283
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the FoFiType1::parse() function in fofi/FoFiType1.cc, when processing PDF files. A remote attacker can perform a denial of service attack.


Affected software

xpdf
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
openSUSE Leap
Ubuntu
Fedora
libpoppler44-debuginfo
libpoppler44
libpoppler58 (Ubuntu package)
poppler-utils (Ubuntu package)
libpoppler-qt4-4
poppler-debugsource
libpoppler60
libpoppler60-debuginfo
poppler-tools-debuginfo
libpoppler-qt4-4-debuginfo
libpoppler-glib8
libpoppler-glib8-debuginfo
poppler-tools
libpoppler-devel
libpoppler-glib-devel
libpoppler-cpp0
typelib-1_0-Poppler-0_18
libpoppler-qt4-devel
libpoppler-cpp0-debuginfo
libpoppler73 (Ubuntu package)
libpoppler73
libpoppler73-32bit-debuginfo
libpoppler73-32bit
libpoppler73-debuginfo
xpdf

How to mitigate CVE-2019-13283

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libpoppler44-debuginfo - update to 0.24.4-14.23.1
libpoppler44 - update to 0.24.4-14.23.1
libpoppler58 (Ubuntu package) - update to 0.41.0-0ubuntu1.15
poppler-utils (Ubuntu package) - addressed in versions 0.41.0-0ubuntu1.15, 0.62.0-2ubuntu2.11
libpoppler-qt4-4 - update to 0.43.0-16.22.1
poppler-debugsource - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler60 - update to 0.43.0-16.22.1
libpoppler60-debuginfo - update to 0.43.0-16.22.1
poppler-tools-debuginfo - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler-qt4-4-debuginfo - update to 0.43.0-16.22.1
libpoppler-glib8 - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler-glib8-debuginfo - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
poppler-tools - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler-devel - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler-glib-devel - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler-cpp0 - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
typelib-1_0-Poppler-0_18 - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler-qt4-devel - update to 0.43.0-16.22.1
libpoppler-cpp0-debuginfo - addressed in versions 0.43.0-16.22.1, 0.62.0-150000.4.9.1
libpoppler73 (Ubuntu package) - update to 0.62.0-2ubuntu2.11
libpoppler73 - update to 0.62.0-150000.4.9.1
libpoppler73-32bit-debuginfo - update to 0.62.0-150000.4.9.1
libpoppler73-32bit - update to 0.62.0-150000.4.9.1
libpoppler73-debuginfo - update to 0.62.0-150000.4.9.1
xpdf - addressed in versions 4.02-1.fc29, 4.02-1.fc30, 4.02-1.fc31

External References

Related Security Bulletins