CVE-2019-12958: Medium severity glyph & cog xpdfreader vulnerability
Published Jun 24, 2019
·Updated
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.
Affected Software
1 affected component
Glyphandcog Xpdfreader=4.01.01
Event History
Jun 24, 2019
CVE Published
via MITRE·11:27 PM
Data Sourced
via MITRE·11:27 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-12958.
2
What is the severity of CVE-2019-12958?
The severity of CVE-2019-12958 is medium with a severity value of 5.5.
3
How can CVE-2019-12958 be triggered?
CVE-2019-12958 can be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when trying to access the second privateDicts array element.
4
What software version is affected by CVE-2019-12958?
Xpdf 4.01.01 is affected by CVE-2019-12958.
5
Is there a fix available for CVE-2019-12958?
Yes, a fix is available for CVE-2019-12958. It is recommended to update to a version that includes the fix.