Description
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
Exploits (4)
nomisec
WRITEUP
by WildWestCyberSecurity · poc
https://github.com/WildWestCyberSecurity/CVE-2019-13288
Scores
CVSS v3
5.5
EPSS
0.2751
EPSS Percentile
96.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-674
Status
published
Products (1)
glyphandcog/xpdfreader
4.01.01
Published
Jul 04, 2019
Tracked Since
Feb 18, 2026