{"api_version":"1","generated_at":"2026-07-23T21:09:47+00:00","cve":"CVE-2019-9587","urls":{"html":"https://cve.report/CVE-2019-9587","api":"https://cve.report/api/cve/CVE-2019-9587.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-9587","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-9587"},"summary":{"title":"CVE-2019-9587","description":"There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-03-06 08:29:00","updated_at":"2019-03-06 23:09:00"},"problem_types":["CWE-400"],"metrics":[],"references":[{"url":"https://forum.xpdfreader.com/viewtopic.php?f=3&t=41263","name":"https://forum.xpdfreader.com/viewtopic.php?f=3&t=41263","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Stack based buffer overflow vulnerability in function md5Round1( ) – xpdf-4.01 - forum.xpdfreader.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://research.loginsoft.com/bugs/stack-based-buffer-overflow-vulnerability-in-function-md5round1-xpdf-4-01/","name":"https://research.loginsoft.com/bugs/stack-based-buffer-overflow-vulnerability-in-function-md5round1-xpdf-4-01/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"CVE-2019-9587: Stack consumption issue in function md5Round1( ) - xpdf-4.01 - Loginsoft Research","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-9587","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9587","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"9587","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glyphandcog","cpe5":"xpdfreader","cpe6":"4.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"9587","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glyphandcog","cpe5":"xpdfreader","cpe6":"4.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-9587","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://forum.xpdfreader.com/viewtopic.php?f=3&t=41263","refsource":"MISC","url":"https://forum.xpdfreader.com/viewtopic.php?f=3&t=41263"},{"name":"https://research.loginsoft.com/bugs/stack-based-buffer-overflow-vulnerability-in-function-md5round1-xpdf-4-01/","refsource":"MISC","url":"https://research.loginsoft.com/bugs/stack-based-buffer-overflow-vulnerability-in-function-md5round1-xpdf-4-01/"}]}},"nvd":{"publishedDate":"2019-03-06 08:29:00","lastModifiedDate":"2019-03-06 23:09:00","problem_types":["CWE-400"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:glyphandcog:xpdfreader:4.01:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"9587","Ordinal":"147453","Title":"CVE-2019-9587","CVE":"CVE-2019-9587","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"9587","Ordinal":"1","NoteData":"There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"9587","Ordinal":"2","NoteData":"2019-03-06","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"9587","Ordinal":"3","NoteData":"2019-03-06","Type":"Other","Title":"Modified"}]}}}