CVE-2019-13289 is a use-after-free vulnerability in the JBIG2Stream::close() function of Xpdf 4.01.01, affecting products like glyphandcog xpdfreader. This vulnerability can be triggered by processing a specially crafted PDF document, for instance, via the pdftoppm tool. With a CVSS score of 7.8 (High), it presents a significant risk, allowing for high confidentiality, integrity, and availability impacts through a low-complexity attack requiring user interaction. Despite its severity, there is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.01.01CPE matchmatch criteria | cpe:2.3:a:glyphandcog:xpdfreader:4.01.01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.