PT-2018-3848 · Poppler+5 · Poppler+5

Pwd

·

Published

2018-11-01

·

Updated

2023-07-20

·

CVE-2018-18897

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Poppler version 0.71.0
Description The issue is related to a memory leak in the GfxState.cc component of the Poppler library, which is used for displaying PDF files. This memory leak occurs due to a resource not being released after its valid lifetime has expired. Exploitation of this issue allows a remote attacker to cause a denial of service.
Recommendations For Poppler version 0.71.0, consider applying a patch or updating to a newer version that fixes the memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc to prevent potential denial of service attacks.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

BDU:2022-06881
CESA-2019_2022
CESA-2019_2713
CVE-2018-18897
DLA-3120-1
MGASA-2019-0092
OPENSUSE-SU-2021:3854-1
OPENSUSE-SU-2021_3854-1
RHSA-2019:2022
RHSA-2019:2713
RHSA-2019_2022
RHSA-2019_2713
SUSE-SU-2021:3854-1
SUSE-SU-2023:2906-1
SUSE-SU-2023:2907-1
USN-4042-1

Affected Products

Astra Linux
Centos
Poppler
Red Hat
Suse
Ubuntu