CVE-2019-13291: Medium severity glyph & cog xpdfreader vulnerability
Published Jul 4, 2019
·Updated
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.
Affected Software
1 affected component
Glyphandcog Xpdfreader=4.01.01
Event History
Jul 4, 2019
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13291?
The severity of CVE-2019-13291 is rated as medium (5.5).
2
How can I trigger the vulnerability in Xpdf 4.01.01?
The vulnerability in Xpdf 4.01.01 can be triggered by sending a crafted PDF document to the pdftops tool.
3
Where is the heap-based buffer over-read located in Xpdf 4.01.01?
In Xpdf 4.01.01, the heap-based buffer over-read is located in the function DCTStream::readScan() at Stream.cc.
4
What type of attack does CVE-2019-13291 make possible?
CVE-2019-13291 might allow an attacker to cause Information Disclosure.