CVE-2019-9587

Source
https://cve.org/CVERecord?id=CVE-2019-9587
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9587.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-9587
Downstream
Published
2019-03-06T08:29:00.277Z
Modified
2026-03-14T09:46:00.644276Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9587.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.01"
            }
        ]
    }
]