CVE-2019-12360
published 2019-05-27CVE-2019-12360: A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted…
PriorityP427high7.1CVSS 3.0
AVLACLPRNUIRSUCHINAH
EPSS
1.12%
62.5th percentile
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < poppler 0.38.0-2 (bookworm) | poppler 0.38.0-2 (bookworm) |
| debian | xpdf | < poppler 0.38.0-2 (bookworm) | poppler 0.38.0-2 (bookworm) |
| freedesktop | poppler | >= 0 < 0.38.0-2 | 0.38.0-2 |
| freedesktop | poppler | >= 0 < 0.38.0-2 | 0.38.0-2 |
| freedesktop | poppler | >= 0 < 0.38.0-2 | 0.38.0-2 |
| freedesktop | poppler | >= 0 < 0.38.0-2 | 0.38.0-2 |
| glyphandcog | xpdfreader | — | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
vendor_redhat·2019-05-27·CVSS 7.1
CVE-2019-12360 [HIGH] CWE-125 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
A stack-based buffer over-read flaw was found in the FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf, where it can be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. This flaw allows an attacker to cause a denial of service or to leak memory data into dump content. The highest threat from this vulnerability is to confidentiality and system availability.
Statement: Red H
Debian
CVE-2019-12360: poppler - A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTr...
vendor_debian·2019·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360: poppler - A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTr...
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
Scope: local
bookworm: resolved (fixed in 0.38.0-2)
bullseye: resolved (fixed in 0.38.0-2)
forky: resolved (fixed in 0.38.0-2)
sid: resolved (fixed in 0.38.0-2)
trixie: resolved (fixed in 0.38.0-2)
GHSA
GHSA-h895-jpgg-q54p: A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType
ghsa_unreviewed·2022-05-24
CVE-2019-12360 [HIGH] GHSA-h895-jpgg-q54p: A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
OSV
CVE-2019-12360: A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType
osv·2019-05-27·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360: A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12360 mingw-poppler: xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
bugzilla·2020-06-25·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360 mingw-poppler: xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
CVE-2019-12360 mingw-poppler: xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
bugzilla·2020-06-25·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2019-12360 poppler: xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
bugzilla·2020-06-25·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360 poppler: xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
CVE-2019-12360 poppler: xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
bugzilla·2020-06-25·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
A stack-based buffer over-read exists in FoFiTrueType::dumpString in
fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by
sending crafted TrueType data in a PDF document to the pdftops tool. It might
allow an attacker to cause Denial of Service or leak memory data into dump
content.
References:
https://forum.xpdfreader.com/viewtopic.php?f=3&t=41801
https://lists.debian.org/debian-lts-announce/2019/06/msg00002.html
Discussion:
Created mingw-poppler tracking bugs for this issue:
Affects: fedora-all [bug 1850881]
Created poppler tracking bugs for this issue:
Affects: fedora-all [bug 1850880]
Created xpdf tracking bugs for this issue:
Affects: epel-all [bug 1850879]
Affe
Bugzilla
CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [epel-all]
bugzilla·2020-06-25·CVSS 7.1
CVE-2019-12360 [HIGH] CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [epel-all]
CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
https://forum.xpdfreader.com/viewtopic.php?f=3&t=41801https://lists.debian.org/debian-lts-announce/2019/06/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EJ3GYFINXANXTQEDN5SON47IJA5277RU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IQBAHQQF2P7E6PL5STST3TGH7VPVXKKQ/https://forum.xpdfreader.com/viewtopic.php?f=3&t=41801https://lists.debian.org/debian-lts-announce/2019/06/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EJ3GYFINXANXTQEDN5SON47IJA5277RU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IQBAHQQF2P7E6PL5STST3TGH7VPVXKKQ/
2019-05-27
Published