First published: Sat Jul 27 2019(Updated: )
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glyph & Cog XpdfReader | =4.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14288 is a vulnerability in Xpdf 4.01.01 that allows for an integer overflow in the JBIG2Bitmap::combine function.
The severity of CVE-2019-14288 is high, with a CVSS score of 7.8.
CVE-2019-14288 allows for an integer overflow in the JBIG2Bitmap::combine function in Xpdf 4.01.01.
To fix CVE-2019-14288, update Xpdf to a version that is not affected by the vulnerability.
You can find more information about CVE-2019-14288 on the Xpdf forum and GitHub repository.