CVE-2019-13288

MEDIUM

Glyphandcog Xpdfreader - Denial of Service

Title source: rule
STIX 2.1

Description

In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

Exploits (4)

nomisec STUB 2 stars
by Fineas · poc
https://github.com/Fineas/CVE-2019-13288-POC
nomisec WRITEUP
by ngtuonghung · poc
https://github.com/ngtuonghung/CVE-2019-13288
nomisec WRITEUP
by WildWestCyberSecurity · poc
https://github.com/WildWestCyberSecurity/CVE-2019-13288
nomisec STUB
by gleaming0 · poc
https://github.com/gleaming0/CVE-2019-13288

Scores

CVSS v3 5.5
EPSS 0.2751
EPSS Percentile 96.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-674
Status published
Products (1)
glyphandcog/xpdfreader 4.01.01
Published Jul 04, 2019
Tracked Since Feb 18, 2026