First published: Sun Sep 08 2019(Updated: )
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glyph & Cog XpdfReader | =4.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16115 is high (7.8).
CVE-2019-16115 affects Xpdf 4.01.01 by causing a stack-based buffer under-read in IdentityFunction::transform, which is used by GfxAxialShading::getColor.
CVE-2019-16115 can be triggered by sending a crafted PDF document to the pdftoppm tool.
An attacker can use a crafted PDF file to cause Denial of Service or potentially execute arbitrary code.
Yes, upgrading to a version of Xpdf that is not affected by CVE-2019-16115 (4.01.02 or later) is recommended.