VDB

GCVE-VVD-MAGEIA-2020-291

GCVE-VVD-MAGEIA-2020-291
Advisory Published
Vulnetix · Advisory published July 10, 2020
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content. (CVE-2019-12360)

Affected Products

VendorProductVersionsPlatforms
Mageiaxpdf0 (affected), 4.02-1.2.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›