CVE-2013-1790: Buffer Overflow
An uninitialized memory read flaw was reported in poppler (fixed in version 0.22.1):
Initialize refLine totally Fixes uninitialized memory read in 1004.pdf.asan.7.3 [1]
[1] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=b1026b5978c385328f2a15a2185c599a563edf91
Other sources
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1790?
CVE-2013-1790 is classified as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2013-1790?
To fix CVE-2013-1790, you need to upgrade to Poppler version 0.22.1 or later.
What type of vulnerability is CVE-2013-1790?
CVE-2013-1790 is an uninitialized memory read vulnerability affecting Poppler.
Which versions of Poppler are affected by CVE-2013-1790?
Poppler versions prior to 0.22.1 are affected by CVE-2013-1790.
Is CVE-2013-1790 fixed in later versions of Poppler?
Yes, CVE-2013-1790 is fixed in Poppler version 0.22.1 and later.