Buffer overflow in xpdf - CVE-2019-9877

 

Buffer overflow in xpdf - CVE-2019-9877

Published: March 21, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36051
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9877
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.


Affected software

xpdf
Arch Linux

How to mitigate CVE-2019-9877

Install update from vendor's website.


External References

Related Security Bulletins