CVE-2019-14267 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 7.05% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-07-29 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| fedoraproject | fedora |
| pdfresurrect project | pdfresurrect |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | pdfresurrect 0.15 - Buffer Overflow | 2019-07-26 |
References
- http://packetstormsecurity.com/files/153767/pdfresurrect-0.15-Buffer-Overflow.html
- https://github.com/enferex/pdfresurrect/commits/master
- https://github.com/snappyJack/pdfresurrect_CVE-2019-14267
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4DBYXYU2VSDJ3NAL54IW2KYD3TZSR33M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXN6W5QTNQJ2LFDCQWKYSMMZ3NPUWP3U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y243C2IFMRFQWHV62JCSHTMQGDDCICNF/
- http://packetstormsecurity.com/files/153767/pdfresurrect-0.15-Buffer-Overflow.html
- https://github.com/enferex/pdfresurrect/commits/master
- https://github.com/snappyJack/pdfresurrect_CVE-2019-14267
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4DBYXYU2VSDJ3NAL54IW2KYD3TZSR33M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXN6W5QTNQJ2LFDCQWKYSMMZ3NPUWP3U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y243C2IFMRFQWHV62JCSHTMQGDDCICNF/
→ the Explorer · watch your stack · NVD