PT-2023-5944 · Poppler+4 · Poppler+4
Published
2023-08-11
·
Updated
2023-12-08
·
CVE-2020-23804
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Poppler version 0.89.0
Description
The issue is related to uncontrolled recursion in the Poppler library for rendering PDF files. This can be exploited by a remote attacker to cause a denial of service via crafted input. The vulnerability affects the
pdfinfo and pdftops components.Recommendations
For Poppler version 0.89.0, consider disabling the
pdfinfo and pdftops functions until a patch is available to prevent potential denial of service attacks.Exploit
Fix
DoS
Improper Resource Release
NULL Pointer Dereference
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Poppler
Suse
Ubuntu