PT-2019-2633 · Poppler+1 · Poppler+1

Published

2019-04-05

·

Updated

2019-09-06

·

CVE-2019-10873

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Poppler version 0.74.0
Description The issue is related to a NULL pointer dereference in the SplashClip::clipAALine function at splash/SplashClip.cc. This could allow a remote attacker to cause a denial of service using a specially crafted PDF document.
Recommendations For Poppler version 0.74.0, consider disabling the SplashClip::clipAALine function as a temporary workaround until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02518
CVE-2019-10873
MGASA-2019-0245
USN-4042-1

Affected Products

Poppler
Ubuntu