Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9878

Опубликовано: 21 мар. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pdfalto_project:pdfalto:0.2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:xpdfreader:xpdf:4.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00229
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 7.8
debian
почти 7 лет назад

There is an invalid memory access in the function GfxIndexedColorSpace ...

CVSS3: 7.8
github
больше 3 лет назад

There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

EPSS

Процентиль: 45%
0.00229
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-125