Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9587

Опубликовано: 06 мар. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:glyphandcog:xpdfreader:4.01:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00337
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

CVSS3: 7.8
debian
почти 7 лет назад

There is a stack consumption issue in md5Round1() located in Decrypt.c ...

CVSS3: 7.8
github
больше 3 лет назад

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

EPSS

Процентиль: 56%
0.00337
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-400