Description
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1706-1 | poppler security update |
Debian DLA |
DLA-2287-1 | poppler security update |
EUVD |
EUVD-2018-13035 | XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc. |
Ubuntu USN |
USN-3865-1 | poppler vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:05:16.857Z
Reserved: 2018-12-25T00:00:00.000Z
Link: CVE-2018-20481
No data.
Status : Modified
Published: 2018-12-26T04:29:00.267
Modified: 2024-11-21T04:01:34.173
Link: CVE-2018-20481
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN