VYPR
Unrated severityNVD Advisory· Published Jul 21, 2021· Updated Aug 4, 2024

CVE-2020-19466

CVE-2020-19466

Description

An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 .

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An invalid read of size 1 in DCTStream::transformDataUnit in PDF2JSON 0.70 allows attackers to cause a denial of service via a crafted PDF.

Vulnerability

An invalid read of size 1 occurs in the DCTStream::transformDataUnit function of PDF2JSON version 0.70 (commit b671b64). This function is part of the DCT (JPEG) decoding stream and is triggered when processing a specially crafted PDF file. The issue was reported in the project's issue tracker [1].

Exploitation

An attacker can exploit this vulnerability by providing a malicious PDF file that causes the invalid read. No authentication or special privileges are required; the victim only needs to open the file with pdf2json. A proof-of-concept (PoC) file is available [1]. The crash is confirmed via Valgrind, showing an invalid read of size 1 at the function DCTStream::transformDataUnit.

Impact

Successful exploitation results in a denial of service (DoS) due to a segmentation fault (SIGSEGV). The application crashes, terminating the PDF processing. No code execution or data disclosure has been demonstrated.

Mitigation

As of the reference [1], no fix has been released for this issue. Users should avoid processing untrusted PDF files with PDF2JSON 0.70. No workaround is available. The project appears to be unmaintained, so upgrading to a patched version is not possible.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.