CVE-2019-14291: Medium severity glyph & cog xpdfreader vulnerability
Published Jul 27, 2019
·Updated
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.
Affected Software
1 affected component
Glyphandcog Xpdfreader=4.01.01
Event History
Jul 27, 2019
CVE Published
via MITRE·06:40 PM
Data Sourced
via MITRE·06:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14291?
CVE-2019-14291 is classified as a high-severity vulnerability due to the potential for out of bounds reads.
2
How do I fix CVE-2019-14291?
To fix CVE-2019-14291, update Xpdf to a version that is not affected, as the vulnerability exists in version 4.01.01.
3
What types of attacks are possible with CVE-2019-14291?
Exploitation of CVE-2019-14291 could potentially lead to application crashes or disclosure of sensitive information.
4
Which software versions are affected by CVE-2019-14291?
CVE-2019-14291 specifically affects Xpdf version 4.01.01.
5
What is the nature of the issue in CVE-2019-14291?
CVE-2019-14291 is an out of bounds read vulnerability specifically occurring in the parse function of GfxPatchMeshShading.