ZeroHour

CVE-2019-9589

PoC ×2
CVSS 3.0
7.8 high
EPSS
1%p66
Published
()
Modified
Description

There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

Vendors
glyphandcog
Products
xpdfreader
Weakness
CWE-476
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.