First published: Sat Jul 27 2019(Updated: )
An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glyph & Cog XpdfReader | =4.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-14294 is considered high due to the potential for exploitation leading to application crashes or arbitrary code execution.
To fix CVE-2019-14294, update Xpdf to the latest version provided by Glyph & Cog that addresses this vulnerability.
CVE-2019-14294 specifically affects Xpdf version 4.01.01.
CVE-2019-14294 is classified as a use-after-free vulnerability, which can lead to out of bounds read issues.
The vendor associated with CVE-2019-14294 is Glyph & Cog, the company behind the XpdfReader software.