HIGH · 7.5

CVE-2020-35376

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

Vulnerability Description

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
XpdfreaderXpdf4.02
FedoraprojectFedora32

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-35376?

CVE-2020-35376 is a vulnerability with a CVSS score of 7.5 (HIGH). Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

How severe is CVE-2020-35376?

CVE-2020-35376 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-35376?

Check the references section above for vendor advisories and patch information. Affected products include: Xpdfreader Xpdf, Fedoraproject Fedora.