CVE-2019-13283

Priority
Description
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in
strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not
ensure the source string has a valid length before making a fixed-length
copy. It can, for example, be triggered by sending a crafted PDF document
to the pdftotext tool. It allows an attacker to use a crafted pdf file to
cause Denial of Service or an information leak, or possibly have
unspecified other impact.
Notes
jdstrandxpdf in koffice is 2.0
ebarrettosince 0.5.12-1 libextractor does not use xpdf anymore.
Package
Source: ipe (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (code not present)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (code not present)
Ubuntu 19.10 (Eoan Ermine):not-affected (code not present)
Ubuntu 20.04 (Focal Fossa):not-affected (code not present)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (code not present)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (code not present)
Ubuntu 19.10 (Eoan Ermine):not-affected (code not present)
Ubuntu 20.04 (Focal Fossa):not-affected (code not present)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (0.62.0-2ubuntu2.9)
Ubuntu 19.10 (Eoan Ermine):not-affected (0.76.1-0ubuntu4)
Ubuntu 20.04 (Focal Fossa):not-affected (0.76.1-0ubuntu4)
Patches:
Upstream:https://gitlab.freedesktop.org/poppler/poppler/commit/c758fc980834882528eeae82568494e46d189cc5
Package
Source: xpdf (LP Ubuntu Debian)
Upstream:not-affected (debian: xpdf in Debian uses poppler, which is fixed)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.10 (Eoan Ermine):needs-triage
Ubuntu 20.04 (Focal Fossa):DNE
More Information

Updated: 2020-04-24 03:53:16 UTC (commit d3f8a6ed481830fb100109a132bef581fc4176fe)