PT-2018-3848 · Poppler+5 · Poppler+5

·

CVE-2018-18897

·

Published

2018-11-01

·

Updated

2023-07-20

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Poppler version 0.71.0
Description The issue is related to a memory leak in the GfxState.cc component of the Poppler library, which is used for displaying PDF files. This memory leak occurs due to a resource not being released after its valid lifetime has expired. Exploitation of this issue allows a remote attacker to cause a denial of service.
Recommendations For Poppler version 0.71.0, consider applying a patch or updating to a newer version that fixes the memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc to prevent potential denial of service attacks.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06881
CESA-2019_2022
CESA-2019_2713
CVE-2018-18897
DLA-3120-1
MGASA-2019-0092
OPENSUSE-SU-2021:3854-1
OPENSUSE-SU-2021_3854-1
RHSA-2019:2022
RHSA-2019:2713
RHSA-2019_2022
RHSA-2019_2713
SUSE-SU-2021:3854-1
SUSE-SU-2023:2906-1
SUSE-SU-2023:2907-1
USN-4042-1

Affected Products

Astra Linux
Centos
Poppler
Red Hat
Suse
Ubuntu