CVE-2019-13283
Published: 04 July 2019
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
ipe Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Not vulnerable
(code not present)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(code not present)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(code not present)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(code not present)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Not vulnerable
(code not present)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
libextractor Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Not vulnerable
(code not present)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(code not present)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(code not present)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(code not present)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Not vulnerable
(code not present)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
poppler Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Not vulnerable
(0.76.1-0ubuntu4)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(0.76.1-0ubuntu4)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(0.76.1-0ubuntu4)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(0.62.0-2ubuntu2.9)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(0.41.0-0ubuntu1.15)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|
|
Patches: Upstream: https://gitlab.freedesktop.org/poppler/poppler/commit/c758fc980834882528eeae82568494e46d189cc5 |
||
xpdf Launchpad, Ubuntu, Debian |
Upstream |
Not vulnerable
(debian: xpdf in Debian uses poppler, which is fixed)
|
Ubuntu 21.04 (Hirsute Hippo) |
Needs triage
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Needs triage
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Needs triage
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Ubuntu 12.04 ESM (Precise Pangolin) |
Does not exist
|