In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://forum.xpdfreader.com/viewtopic.php?f=3&t=41818 | vendor advisory exploit |