Bug 1850876 (CVE-2019-12360)

Summary: CVE-2019-12360 xpdf: buffer over-read via crafted PDF document leads to DoS or memory leak
Product: [Other] Security Response Reporter: msiddiqu
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: caillon+fedoraproject, feborges, gnome-sig, huzaifas, john.j5live, manisandro, mclasen, mkasik, pertusus, rdieter, rhughes, rstrode, spotrh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: poppler 0.32.0 Doc Type: If docs needed, set a value
Doc Text:
A stack-based buffer over-read flaw was found in the FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf, where it can be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. This flaw allows an attacker to cause a denial of service or to leak memory data into dump content. The highest threat from this vulnerability is to confidentiality and system availability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1850877, 1850879, 1850880, 1850881, 1850904, 1850905    
Bug Blocks: 1850878    

Description msiddiqu 2020-06-25 05:36:25 UTC
A stack-based buffer over-read exists in FoFiTrueType::dumpString in
fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by
sending crafted TrueType data in a PDF document to the pdftops tool. It might
allow an attacker to cause Denial of Service or leak memory data into dump
content.

References:

https://forum.xpdfreader.com/viewtopic.php?f=3&t=41801
https://lists.debian.org/debian-lts-announce/2019/06/msg00002.html

Comment 1 msiddiqu 2020-06-25 05:39:29 UTC
Created mingw-poppler tracking bugs for this issue:

Affects: fedora-all [bug 1850881]


Created poppler tracking bugs for this issue:

Affects: fedora-all [bug 1850880]


Created xpdf tracking bugs for this issue:

Affects: epel-all [bug 1850879]
Affects: fedora-all [bug 1850877]