CVE-2019-13288: Medium severity glyph & cog xpdfreader vulnerability
Published Jul 4, 2019
·Updated
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
Affected Software
1 affected component
Glyphandcog Xpdfreader=4.01.01
Event History
Jul 4, 2019
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13288?
CVE-2019-13288 is categorized as a Denial of Service (DoS) vulnerability due to potential infinite recursion.
2
How do I fix CVE-2019-13288?
To mitigate CVE-2019-13288, it is recommended to upgrade to the latest version of Xpdf that addresses this vulnerability.
3
What does CVE-2019-13288 affect?
CVE-2019-13288 specifically affects Xpdf version 4.01.01.
4
Can CVE-2019-13288 be exploited remotely?
Yes, CVE-2019-13288 can be exploited remotely, allowing an attacker to carry out a DoS attack.
5
What is the cause of the vulnerability in CVE-2019-13288?
The vulnerability in CVE-2019-13288 is caused by the Parser::getObj() function in Parser.cc that may lead to infinite recursion when processing crafted files.