Bug 1106985 - VUL-1: xpdf: CVE-2018-16369 xpdf: heap-based buffer over-read via a crafted pdf file
Summary: VUL-1: xpdf: CVE-2018-16369 xpdf: heap-based buffer over-read via a crafted p...
Status: RESOLVED DUPLICATE of bug 1106879
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: ---
Assignee: Peter Simons
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/213677/
Whiteboard: CVSSv3:RedHat:CVE-2018-16369:3.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2018-09-04 06:31 UTC by Karol Babioch
Modified: 2019-12-10 07:51 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-09-04 06:31:43 UTC
rh#1624990

A flaw was found in Xpdf 4.00. The XRef::fetch in XRef.cc allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.


References:
https://github.com/TeamSeri0us/pocs/tree/master/xpdf

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1624990
Comment 1 Karol Babioch 2018-09-04 06:41:41 UTC
Duplicate.

*** This bug has been marked as a duplicate of bug 1106879 ***