Bug 1082840 (CVE-2018-7455) - VUL-1: CVE-2018-7455: xpdf: An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc allows attackers to launch denial of service via a specific pdf file
Summary: VUL-1: CVE-2018-7455: xpdf: An out-of-bounds read in JPXStream::readTilePart ...
Status: RESOLVED INVALID
Alias: CVE-2018-7455
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Peter Simons
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/200815/
Whiteboard: maint:planned:update CVSSv2:NVD:CVE-2...
Keywords:
Depends on:
Blocks: 1133493
  Show dependency treegraph
 
Reported: 2018-02-26 13:08 UTC by Karol Babioch
Modified: 2023-06-14 14:38 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-02-26 13:08:10 UTC
CVE-2018-7455

An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00
allows attackers to launch denial of service via a specific pdf file, as
demonstrated by pdftohtml.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-7455
http://www.cvedetails.com/cve/CVE-2018-7455/
https://forum.xpdfreader.com/viewtopic.php?f=3&t=654&p=819#p819
https://forum.xpdfreader.com/viewtopic.php?f=3&t=654&p=819#p819
Comment 1 Peter Simons 2018-06-21 09:27:23 UTC
Upstream commented: 

> I think I've tracked down the problem here.
> I'm working on a fix for it.

That was over a year ago. No observable progress has been made since then.
Comment 2 Petr Gajdos 2023-06-12 11:36:46 UTC
https://github.com/skysider/FuzzVuln/blob/master/xpdf_pdftohtml_invalid_pointer_dereference_JPXStream_close.pdf

I do not get any crash or valgrind error with pdftohtml from devel,15,12,11sp1/poppler.

Since xpdf is not maintained anymore I suggest to close.