CVE-2019-13286: Medium severity glyph & cog xpdfreader vulnerability
Published Jul 4, 2019
·Updated
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.
Affected Software
4 affected components
Glyphandcog Xpdfreader=4.01.01
Fedoraproject Fedora=29
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Event History
Jul 4, 2019
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13286?
The severity of CVE-2019-13286 is medium with a severity value of 5.5.
2
How does CVE-2019-13286 affect Xpdf?
CVE-2019-13286 affects Xpdf version 4.01.01.
3
How can CVE-2019-13286 be triggered?
CVE-2019-13286 can be triggered by sending a crafted PDF document to the pdftoppm tool.
4
What is the potential impact of CVE-2019-13286?
CVE-2019-13286 might allow an attacker to cause information disclosure.
5
Are there any references related to CVE-2019-13286?
Yes, you can find references related to CVE-2019-13286 at the following URLs: [URLs here]