A null pointer dereference vulnerability tracked as CVE-2019-9589 affects Xpdf 4.01 in the function PSOutputDev::setupResources() within PSOutputDev.cc. The flaw can be triggered when the pdftops binary processes a crafted PDF file, causing a segmentation fault and resulting in a denial-of-service condition. The issue was reported by the ACE Team at Loginsoft, which published debugger output, source-code context, and a proof-of-concept demonstrating the crash path.
The disclosure notes indicate the vendor was notified before public release, and the affected software is distributed through the Xpdf project’s download channel. Organizations using Xpdf, especially workflows that automatically convert untrusted PDF files with pdftops, face a risk of service interruption and should verify whether vulnerable 4.01 deployments remain in use and apply an updated version or compensating controls where available.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Xpdf 4.01 null pointer dereference vulnerability in PSOutputDev::setupResources() was publicly disclosed. The flaw could cause a denial of service through a segmentation fault when pdftops processed a crafted PDF file.
ACE Team at Loginsoft disclosed the null pointer dereference vulnerability later assigned CVE-2019-9589 to the vendor. The issue affected Xpdf 4.01 and could be triggered via a crafted PDF processed by pdftops.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.