Advisory text to describe the update. Wrap lines at ~75 chars. A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. . MGASA-2020-0291 - Updated xpdf packages fix security vulnerability Publication date: 10 Jul 2020 URL: https://advisories.mageia.org/MGASA-2020-0291.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12360 Advisory text to describe the update. Wrap lines at ~75 chars. A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content. (CVE-2019-12360) References: - https://bugs.mageia.org/show_bug.cgi?id=26920 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.