PT-2018-3848 · Poppler+5 · Poppler+5
Pwd
·
Publicado
2018-11-01
·
Atualizado
2023-07-20
·
CVE-2018-18897
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Poppler version 0.71.0
Description
The issue is related to a memory leak in the GfxState.cc component of the Poppler library, which is used for displaying PDF files. This memory leak occurs due to a resource not being released after its valid lifetime has expired. Exploitation of this issue allows a remote attacker to cause a denial of service.
Recommendations
For Poppler version 0.71.0, consider applying a patch or updating to a newer version that fixes the memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc to prevent potential denial of service attacks.
Exploit
Correção
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astra Linux
Centos
Poppler
Red Hat
Suse
Ubuntu