The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kdegraphics-develUpgrade gpdfUpgrade xpdfUpgrade kdegraphics | Dec 1, 2016 | Dec 21, 2009 |
| Debian | — | Upgrade xpdfUpgrade poppler | Jul 30, 2024 | Dec 21, 2009 |
| Gentoo Linux | — | Upgrade app-text/xpdf. | Oct 30, 2017 | Dec 21, 2009 |
| Suse | — | Upgrade libpoppler-qt4-3Upgrade libpoppler4Upgrade libpoppler-glib4Upgrade poppler-tools | Feb 17, 2015 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub