CVE-2019-13282: High severity glyph & cog xpdfreader vulnerability
Published Jul 4, 2019
·Updated
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Affected Software
4 affected components
Glyphandcog Xpdfreader=4.01.01
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Event History
Jul 4, 2019
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13282?
The severity of CVE-2019-13282 is high with a CVSS score of 7.8.
2
How can I mitigate the heap-based buffer over-read vulnerability in Xpdf 4.01.01 (CVE-2019-13282)?
To mitigate the vulnerability, ensure you update Xpdf to a version where the issue has been patched.
3
Is there a way to trigger the heap-based buffer over-read vulnerability in Xpdf 4.01.01 (CVE-2019-13282)?
The vulnerability can be triggered by using a large index for samples in SampledFunction::transform in Function.cc or by sending a crafted PDF document to the pdftotext tool.