ArchLinux: 201910-10: xpdf: arbitrary code execution
Summary
Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.
Resolution
Upgrade to 4.02-1.
# pacman -Syu "xpdf>=4.02-1"
The problem has been fixed upstream in version 4.02.
References
https://bugs.archlinux.org/task/63980 ;t=41885 https://security.archlinux.org/CVE-2019-16927
Workaround
None.