CVE-2019-14289Integer Overflow or Wraparound in Xpdfreader

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 62.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 27
Latest updateMay 24

Description

An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-52ph-9rmp-qw5c: An issue was discovered in Xpdf 42022-05-24
OSV
CVE-2019-14289: An issue was discovered in Xpdf 42019-07-27
CVEList
CVE-2019-14289: An issue was discovered in Xpdf 42019-07-27

📋Vendor Advisories

1
Debian
CVE-2019-14289: xpdf - An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the fun...2019

💬Community

3
Bugzilla
CVE-2019-14289 xpdf: integer overflow in function JBIG2Bitmap::combine in JBIG2Stream.cc [epel-all]2019-11-13
Bugzilla
CVE-2019-14289 xpdf: integer overflow in function JBIG2Bitmap::combine in JBIG2Stream.cc2019-11-13
Bugzilla
CVE-2019-14289 xpdf: integer overflow in function JBIG2Bitmap::combine in JBIG2Stream.cc [fedora-all]2019-11-13
CVE-2019-14289 — Integer Overflow or Wraparound | cvebase