CVE-2019-14288Integer Overflow or Wraparound in Xpdfreader

Severity
7.8HIGHNVD
EPSS
0.2%
top 57.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 27
Latest updateMay 24

Description

An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-4h82-f35f-jvf5: An issue was discovered in Xpdf 42022-05-24
OSV
CVE-2019-14288: An issue was discovered in Xpdf 42019-07-27
CVEList
CVE-2019-14288: An issue was discovered in Xpdf 42019-07-27

📋Vendor Advisories

1
Debian
CVE-2019-14288: xpdf - An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the fun...2019

💬Community

3
Bugzilla
CVE-2019-14288 xpdf: integer overflow in function JBIG2Bitmap::combine in JBIG2Stream.cc2019-11-13
Bugzilla
CVE-2019-14288 xpdf: integer overflow in function JBIG2Bitmap::combine in JBIG2Stream.cc [epel-all]2019-11-13
Bugzilla
CVE-2019-14288 xpdf: integer overflow in function JBIG2Bitmap::combine in JBIG2Stream.cc [fedora-all]2019-11-13
CVE-2019-14288 — Integer Overflow or Wraparound | cvebase