There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xpdf | Xpdfreader | 4.03 (including) | 4.03 (including) |
| Ipe | Ubuntu | bionic | * |
| Ipe | Ubuntu | focal | * |
| Ipe | Ubuntu | impish | * |
| Ipe | Ubuntu | kinetic | * |
| Ipe | Ubuntu | lunar | * |
| Ipe | Ubuntu | mantic | * |
| Ipe | Ubuntu | oracular | * |
| Ipe | Ubuntu | trusty | * |
| Ipe | Ubuntu | xenial | * |
| Texlive-bin | Ubuntu | bionic | * |
| Texlive-bin | Ubuntu | focal | * |
| Texlive-bin | Ubuntu | kinetic | * |
| Texlive-bin | Ubuntu | lunar | * |
| Texlive-bin | Ubuntu | mantic | * |
| Texlive-bin | Ubuntu | oracular | * |
| Texlive-bin | Ubuntu | trusty | * |
| Texlive-bin | Ubuntu | xenial | * |
| Xpdf | Ubuntu | bionic | * |
| Xpdf | Ubuntu | impish | * |
| Xpdf | Ubuntu | kinetic | * |
| Xpdf | Ubuntu | lunar | * |
| Xpdf | Ubuntu | mantic | * |
| Xpdf | Ubuntu | oracular | * |
| Xpdf | Ubuntu | trusty | * |
| Xpdf | Ubuntu | xenial | * |