First published: Wed Mar 06 2019(Updated: )
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glyph & Cog XpdfReader | =4.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9587 has a severity rating that could lead to Denial of Service due to stack consumption issues.
To fix CVE-2019-9587, upgrade to the latest version of XpdfReader that addresses this vulnerability.
CVE-2019-9587 affects XpdfReader version 4.01, particularly its md5Round1() function.
CVE-2019-9587 is a stack consumption vulnerability that can lead to a segmentation fault.
An attacker can exploit CVE-2019-9587 by sending a crafted PDF file to the pdfimages binary.