VDB
GCVE-110-MAGEIA-2021-112
GCVE-110-MAGEIA-2021-112
Advisory Published
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state)
SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which
causes an `heap-use-after-free` problem. The codes of a previous fix for nested
Type 3 characters wasn't correctly handling the case where a Type 3 char
referred to another char in the same Type 3 font (CVE-2020-25725).
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference
in a Type 1C font charstring, related to the FoFiType1C::getOp() function
(CVE-2020-35376).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | xpdf | 0 (affected), 4.03-1.mga7 (unaffected), 4.03-1.mga7 (unaffected), 0 (affected) | — |
| Mageia | xpdf | 4.03-1.mga8 (unaffected), 0 (affected), 4.03-1.mga8 (unaffected), 0 (affected) | — |
| Mageia | exaile | 0 (affected), 4.1.0-1.mga8 (unaffected) | — |
Aliases
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.