VDB

GCVE-110-MAGEIA-2021-112

GCVE-110-MAGEIA-2021-112
Advisory Published
Vulnetix · Advisory published March 4, 2021
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font (CVE-2020-25725). Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function (CVE-2020-35376).

Affected Products

VendorProductVersionsPlatforms
Mageiaxpdf0 (affected), 4.03-1.mga7 (unaffected), 4.03-1.mga7 (unaffected), 0 (affected)
Mageiaxpdf4.03-1.mga8 (unaffected), 0 (affected), 4.03-1.mga8 (unaffected), 0 (affected)
Mageiaexaile0 (affected), 4.1.0-1.mga8 (unaffected)

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›