Description
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1939-1 | poppler security update |
EUVD |
EUVD-2019-4089 | A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:24:38.374Z
Reserved: 2019-05-30T00:00:00.000Z
Link: CVE-2019-12493
No data.
Status : Modified
Published: 2019-05-31T02:29:00.227
Modified: 2024-11-21T04:22:57.860
Link: CVE-2019-12493
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD