CVE-2019-15860NULL Pointer Dereference in Xpdfreader

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 62.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 3
Latest updateMay 24

Description

Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-36ff-j8p5-6r9r: Xpdf 22022-05-24
OSV
CVE-2019-15860: Xpdf 22019-09-03
CVEList
CVE-2019-15860: Xpdf 22019-09-03

📋Vendor Advisories

1
Debian
CVE-2019-15860: xpdf - Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a ve...2019

💬Community

3
Bugzilla
CVE-2019-15860 xpdf: Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc [fedora-all]2019-10-01
Bugzilla
CVE-2019-15860 xpdf: Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc [epel-all]2019-10-01
Bugzilla
CVE-2019-15860 Xpdf: Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc2019-10-01
CVE-2019-15860 — NULL Pointer Dereference in Xpdfreader | cvebase