CVE-2013-1788: Buffer Overflow
A number of invalid memory access flaws were reported in poppler (fixed in version 0.22.1):
- Fix invalid memory access in 1150.pdf.asan.8.69 [1]. - Fix invalid memory access in 2030.pdf.asan.69.463 [2]. - Fix another invalid memory access in 1091.pdf.asan.72.42 [3]. - Fix invalid memory accesses in 1091.pdf.asan.72.42 [4]. - Fix invalid memory accesses in 1036.pdf.asan.23.17 [5].
[1] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=8b6dc55e530b2f5ede6b9dfb64aafdd1d5836492 [2] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=e14b6e9c13d35c9bd1e0c50906ace8e707816888 [3] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=0388837f01bc467045164f9ddaff787000a8caaa [4] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=957aa252912cde85d76c41e9710b33425a82b696 [5] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=bbc2d8918fe234b7ef2c480eb148943922cc0959
Other sources
poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1788?
CVE-2013-1788 is classified as a high-severity vulnerability due to its potential to cause application crashes and exploit memory corruption.
How do I fix CVE-2013-1788?
To fix CVE-2013-1788, upgrade Poppler to version 0.22.1 or later.
What are the consequences of CVE-2013-1788?
CVE-2013-1788 can lead to invalid memory access, causing an application crash or the potential execution of arbitrary code.
Which versions of Poppler are affected by CVE-2013-1788?
CVE-2013-1788 affects all Poppler versions prior to 0.22.1.
Is CVE-2013-1788 still a threat in the latest Poppler versions?
No, CVE-2013-1788 has been addressed in versions of Poppler after 0.22.1, mitigating the vulnerability.