There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xpdfreader | Glyphandcog | 4.01 (including) | 4.01 (including) |
Ipe | Ubuntu | cosmic | * |
Ipe | Ubuntu | trusty | * |
Libextractor | Ubuntu | cosmic | * |
Libextractor | Ubuntu | trusty | * |
Poppler | Ubuntu | trusty | * |
Texlive-bin | Ubuntu | trusty | * |
Xpdf | Ubuntu | cosmic | * |
Xpdf | Ubuntu | disco | * |
Xpdf | Ubuntu | eoan | * |
Xpdf | Ubuntu | hirsute | * |
Xpdf | Ubuntu | impish | * |
Xpdf | Ubuntu | trusty | * |
Xpdf | Ubuntu | xenial | * |