First published: Sat Dec 26 2020(Updated: )
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdfreader Xpdf | =4.02 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35376 is a vulnerability in Xpdf 4.02 that allows stack consumption due to an incorrect subroutine reference in a Type 1C font charstring.
Xpdfreader Xpdf version 4.02 is affected by CVE-2020-35376.
CVE-2020-35376 has a severity level of 7.5 (high).
To fix CVE-2020-35376, you should update Xpdfreader Xpdf to a version that is not affected by the vulnerability.
Yes, Fedora 32 is affected by CVE-2020-35376.