PT-2019-6287 · Poppler+5 · Poppler+5

Published

2019-03-15

·

Updated

2023-02-11

·

CVE-2019-9903

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Poppler version 0.74.0
Description The issue is related to the function Dict::find() in the Dict.cc component of the Poppler library, which is used for displaying PDF files. It is caused by the PDFDoc::markObject function in PDFDoc.cc mishandling dict marking, leading to stack consumption. This can be triggered by passing a crafted PDF file to the pdfunite binary, potentially allowing a remote attacker to cause a denial of service.
Recommendations For Poppler version 0.74.0, consider updating to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-06890
CESA-2019_2713
CVE-2019-9903
DLA-3120-1
MGASA-2019-0244
MGASA-2019-0245
OPENSUSE-SU-2021:3854-1
OPENSUSE-SU-2021_3854-1
RHSA-2019:2713
RHSA-2019_2713
SUSE-SU-2021:3854-1
SUSE-SU-2022:1723-1
SUSE-SU-2022_1723-1
USN-4042-1

Affected Products

Astra Linux
Centos
Poppler
Red Hat
Suse
Ubuntu