A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade poppler | Jun 7, 2019 | May 27, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade popplerUpgrade poppler-utilsUpgrade poppler-qtUpgrade poppler-glib | Feb 22, 2021 | May 27, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade poppler-qtUpgrade poppler-utilsUpgrade poppler-glibUpgrade poppler | Jan 20, 2021 | May 27, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade poppler-qtUpgrade poppler-utilsUpgrade poppler-glibUpgrade poppler | Dec 16, 2020 | May 27, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 27, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub