
CVE-2019-13288 analysis repository: bundles the Xpdf PDF parser source and documentation to reproduce, analyze, and patch the vulnerable parsing logic.
version 4.02 2019-sep-25
The Xpdf software and documentation are copyright 1996-2019 Glyph & Cog, LLC.
Email: [email protected] WWW: http://www.xpdfreader.com/
The PDF data structures, operators, and specification are documented in ISO 32000-2:2017.
Xpdf is an open source viewer for Portable Document Format (PDF) files. (These are also sometimes also called 'Acrobat' files, from the name of Adobe's PDF software.) The Xpdf project also includes a PDF text extractor, PDF-to-PostScript converter, and various other utilities.
The Xpdf viewer uses the Qt cross-platform GUI toolkit. The other command line utilties do not require Qt.
Xpdf is licensed under the GNU General Public License (GPL), version 2 or 3. This means that you can distribute derivatives of Xpdf under any of the following:
The Xpdf source package includes the text of both GPL versions: COPYING for GPL v2, COPYING3 for GPL v3.
Please note that Xpdf is NOT licensed under "any later version" of the GPL, as I have no idea what those versions will look like.
If you are redistributing unmodified copies of Xpdf (or any of the Xpdf tools) in binary form, you need to include all of the documentation: README, man pages (or help files), COPYING, and COPYING3.
If you want to incorporate the Xpdf source code into another program (or create a modified version of Xpdf), and you are distributing that program, you have two options: release your program under the GPL (v2 and/or v3), or purchase a commercial Xpdf source license.
If you're interested in commercial licensing, please see the Glyph & Cog web site:
http://www.glyphandcog.com/
Xpdf uses the Qt toolkit and runs on Linux, Windows, and OS X -- and probably other systems that have a Qt port.
The non-GUI command line utilities (pdftops, pdftotext, pdftohtml, pdfinfo, pdffonts, pdfdetach, pdftoppm, pdftopng, and pdfimages) run on Linux, Windows, and OS X -- and should run on pretty much any system with a decent C++ compiler.
If you compile Xpdf for a system not listed on the web page, please let me know. If you're willing to make your binary available by ftp or on the web, I'll be happy to add a link from the Xpdf web page. I have decided not to host any binaries I didn't compile myself (for disk space and support reasons).
If you can't get Xpdf to compile on your system, send me email and I'll try to help.
The latest version is available from:
Source code and several precompiled executables are available.
Announcements of new versions are posted to comp.text.pdf and emailed to a list of people. If you'd like to receive email notification of new versions, just let me know.
To run xpdf, simply type:
xpdf file.pdf
To generate a PostScript file, run pdftops:
pdftops file.pdf
To generate a plain text file, run pdftotext:
pdftotext file.pdf
There are several additional utilities (which are fully described in their man pages):
pdftohtml -- converts a PDF file to HTML pdfinfo -- dumps a PDF file's Info dictionary (plus some other useful information) pdffonts -- lists the fonts used in a PDF file along with various information for each font pdfdetach -- lists or extracts embedded files (attachments) from a PDF file pdftoppm -- converts a PDF file to a series of PPM/PGM/PBM-format bitmaps pdftopng -- converts a PDF file to a series of PNG image files pdfimages -- extracts the images from a PDF file
Command line options and many other details are described in the man pages: xpdf(1), etc.
All of these utilities read an optional configuration file: see the xpdfrc(5) man page.
See the separate file, INSTALL.
If you find a bug in Xpdf, i.e., if it prints an error message, crashes, or incorrectly displays a document, and you don't see that bug listed here, please send me email, with a pointer (URL, ftp site, etc.) to the PDF file.
Xpdf uses the following libraries:
Thanks to:
Various people have contributed modifications made for use by the pdftex project:
Adobe Systems Inc., PostScript Language Reference, 3rd ed. Addison-Wesley, 1999, ISBN 0-201-37922-8. [The official PostScript manual.]
Adobe Systems, Inc., The Type 42 Font Format Specification, Adobe Developer Support Technical Specification #5012. 1998. http://partners.adobe.com/asn/developer/pdfs/tn/5012.Type42_Spec.pdf [Type 42 is the format used to embed TrueType fonts in PostScript files.]
Adobe Systems, Inc., Adobe CMap and CIDFont Files Specification, Adobe Developer Support Technical Specification #5014. 1995. http://www.adobe.com/supportservice/devrelations/PDFS/TN/5014.CIDFont_Spec.pdf [CMap file format needed for Japanese and Chinese font support.]
Adobe Systems, Inc., Adobe-Japan1-4 Character Collection for CID-Keyed Fonts, Adobe Developer Support Technical Note #5078. 2000. http://partners.adobe.com/asn/developer/PDFS/TN/5078.CID_Glyph.pdf [The Adobe Japanese character set.]
Adobe Systems, Inc., Adobe-GB1-4 Character Collection for CID-Keyed Fonts, Adobe Developer Support Technical Note #5079. 2000. http://partners.adobe.com/asn/developer/pdfs/tn/5079.Adobe-GB1-4.pdf [The Adobe Chinese GB (simplified) character set.]
Adobe Systems, Inc., Adobe-CNS1-3 Character Collection for CID-Keyed Fonts, Adobe Developer Support Technical Note #5080. 2000. http://partners.adobe.com/asn/developer/PDFS/TN/5080.CNS_CharColl.pdf [The Adobe Chinese CNS (traditional) character set.]
Adobe Systems Inc., Supporting the DCT Filters in PostScript Level 2, Adobe Developer Support Technical Note #5116. 1992. http://www.adobe.com/supportservice/devrelations/PDFS/TN/5116.PS2_DCT.PDF [Description of the DCTDecode filter parameters.]
Adobe Systems Inc., Open Prepress Interface (OPI) Specification - Version 2.0, Adobe Developer Support Technical Note #5660. 2000. http://partners.adobe.com/asn/developer/PDFS/TN/5660.OPI_2.0.pdf
Adobe Systems Inc., CMap files. ftp://ftp.oreilly.com/pub/examples/nutshell/cjkv/adobe/ [The actual CMap files for the 16-bit CJK encodings.]