CVE-2020-35376: High severity xpdf vulnerability
Published Dec 26, 2020
·Updated
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
Affected Software
3 affected components
Xpdfreader Xpdf=4.02
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Dec 26, 2020
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
Description
Frequently Asked Questions
1
What is CVE-2020-35376?
CVE-2020-35376 is a vulnerability in Xpdf 4.02 that allows stack consumption due to an incorrect subroutine reference in a Type 1C font charstring.
2
How does CVE-2020-35376 affect Xpdfreader Xpdf?
Xpdfreader Xpdf version 4.02 is affected by CVE-2020-35376.
3
What is the severity of CVE-2020-35376?
CVE-2020-35376 has a severity level of 7.5 (high).
4
How can I fix CVE-2020-35376 in Xpdfreader Xpdf?
To fix CVE-2020-35376, you should update Xpdfreader Xpdf to a version that is not affected by the vulnerability.
5
Is Fedora 32 affected by CVE-2020-35376?
Yes, Fedora 32 is affected by CVE-2020-35376.