VDB

CVE-2019-12515

CVE-2019-12515 REJECTED CVSS 7.099999904632568 HIGH

There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service.

EPSS 1.78% · 76.3th percentile

Risk Scores

CVSS 3.0
7.099999904632568
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS Score
1.78%
76.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpoppler0.41.0-0ubuntu1.5, 0.41.0-0ubuntu1, 0.41.0-0ubuntu1.1
Ubuntu:18.04:LTSpoppler0.57.0-2ubuntu4, 0.57.0-2ubuntu5, 0.62.0-1ubuntu1

Timeline

  • Jun 1, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›