CVE-2019-13291
Published: April 7, 2019
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.
MEDIUM
CVSS v3: 5.5
CVSS v3: 5.5
Status
DocFilters Release | Package | State | Justification | Comment |
---|---|---|---|---|
25.1 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.4 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.4.0 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.3 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.2.1 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.2 | xpdf (4.05) | Not Affected | Code Not Present | 4.05 does not match CVE configuration. |
24.1 | xpdf (3.02) | Not Affected | Code Not Present | 3.02 does not match CVE configuration. |
23.3 | xpdf (3.02) | Not Affected | Code Not Present | 3.02 does not match CVE configuration. |
23.2.1 | xpdf (3.02) | Not Affected | Code Not Present | 3.02 does not match CVE configuration. |
23.2 | xpdf (3.02) | Not Affected | Code Not Present | 3.02 does not match CVE configuration. |
23.1 | xpdf (3.02) | Not Affected | Code Not Present | 3.02 does not match CVE configuration. |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
NONE
Base Score
5.5
Base Severity
MEDIUM
Confidentiality Impact
HIGH
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Version
3.0