Bugzilla – Bug 1106985
VUL-1: xpdf: CVE-2018-16369 xpdf: heap-based buffer over-read via a crafted pdf file
Last modified: 2019-12-10 07:51:42 UTC
rh#1624990 A flaw was found in Xpdf 4.00. The XRef::fetch in XRef.cc allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453. References: https://github.com/TeamSeri0us/pocs/tree/master/xpdf References: https://bugzilla.redhat.com/show_bug.cgi?id=1624990
Duplicate. *** This bug has been marked as a duplicate of bug 1106879 ***