PT-2019-2633 · Poppler+1 · Poppler+1
Published
2019-04-05
·
Updated
2019-09-06
·
CVE-2019-10873
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Poppler version 0.74.0
Description
The issue is related to a NULL pointer dereference in the
SplashClip::clipAALine function at splash/SplashClip.cc. This could allow a remote attacker to cause a denial of service using a specially crafted PDF document.Recommendations
For Poppler version 0.74.0, consider disabling the
SplashClip::clipAALine function as a temporary workaround until a patch is available.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Poppler
Ubuntu