5.5
CVSSv3

CVE-2019-13288

Published: 04/07/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

glyphandcog xpdfreader 4.01.01

Github Repositories

POC for Xpdf 404 Infinite Stack Recursion This Repo contains crafted pdfs which trigger multiple vulnerabilities in Xpdf v404 which causes an infinite stack recursion Any attacker could use this vulnerability to cause a DoS attack if the binary was running as a service This is similar to CVE-2019-13288 POC Run any of the crashing files labelled crash0 to crash16 with the pd

CVE-2019-13288-POC xpdf/install/bin/pdftotext /pocpdf In Xpdf 40101, the Parser::getObj() function in Parsercc may cause infinite recursion via a crafted file A remote attacker can leverage this for a DoS attack This is similar to CVE-2018-16646