CVE-2019-12958

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
25/06/2019
Last modified:
07/11/2023

Description

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:glyphandcog:xpdfreader:4.01.01:*:*:*:*:*:*:*