Vulnerability Description
An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pdfresurrect Project | Pdfresurrect | < 0.18 |
| Fedoraproject | Fedora | 29 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://github.com/enferex/pdfresurrect/commit/0c4120fffa3dffe97b95c486a120eded8Patch
- https://github.com/enferex/pdfresurrect/compare/v0.17...v0.18Patch
- https://lists.debian.org/debian-lts-announce/2020/12/msg00002.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://github.com/enferex/pdfresurrect/commit/0c4120fffa3dffe97b95c486a120eded8Patch
- https://github.com/enferex/pdfresurrect/compare/v0.17...v0.18Patch
- https://lists.debian.org/debian-lts-announce/2020/12/msg00002.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2019-14934?
CVE-2019-14934 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.
How severe is CVE-2019-14934?
CVE-2019-14934 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14934?
Check the references section above for vendor advisories and patch information. Affected products include: Pdfresurrect Project Pdfresurrect, Fedoraproject Fedora, Debian Debian Linux.