CVE-2013-1789: Null Pointer Dereference
splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.
Other sources
Two bugs that lead to a denial of service (crash) were reported in poppler (fixed in version 0.22.1):
- Fix crash in broken file 1031.pdf.asan.48.15 [1]. - Do not crash in broken documents like 1007.pdf.asan.48.4 [2].
[1] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=a9b8ab4657dec65b8b86c225d12c533ad7e984e2 [2] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=a205e71a2dbe0c8d4f4905a76a3f79ec522eacec
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1789?
CVE-2013-1789 is classified as a denial of service vulnerability.
How do I fix CVE-2013-1789?
To fix CVE-2013-1789, update poppler to version 0.22.1 or later.
What software versions are affected by CVE-2013-1789?
CVE-2013-1789 affects poppler versions prior to 0.22.1, including versions up to 0.22.0.
What types of attacks can CVE-2013-1789 facilitate?
CVE-2013-1789 allows context-dependent attackers to trigger a crash via specific function manipulations.
Are there any workarounds for CVE-2013-1789?
There are no widely recognized workarounds for CVE-2013-1789 other than upgrading to a patched version.