TROYANOSYVIRUS
Back to CVEs

CVE-2019-13282

HIGH
7.8

Description

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

This product uses data from the NVD API but is not endorsed or certified by the NVD.