CVE-2019-12958
Last modified
CVE-2019-12958 is a vulnerability of currently unknown severity. In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Glyphandcog | Xpdfreader | 4.01.01 |
References
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=41815Exploit, Third Party Advisory
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=41815Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12958?
How severe is CVE-2019-12958?
How do I fix CVE-2019-12958?
Are you affected by CVE-2019-12958?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
