In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13289.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "4.01.01" } ] } ]