CVE-2013-7296: Buffer Overflow
Poppler was recently reported to be vulnerable to a flaw, which can be exploited by malicious people to cause a DoS (Denial of Service) in an application using the library.
The vulnerability is caused due to a format string error when handling extraneous bytes within a segment in the "JBIG2Stream::readSegments()" method in JBIG2Stream.cc, which can be exploited to cause a crash.
The issue is said to be fixed in Poppler 0.24.5.
References: https://bugs.gentoo.org/showbug.cgi?id=496770 https://bugs.kde.org/showbug.cgi?id=328511 (okular)
Commit: http://cgit.freedesktop.org/poppler/poppler/commit/?id=58e04a08afee39370283c494ee2e4e392fd3b684
Other sources
The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted PDF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/popplerto a version that resolves this vulnerability.Fixed in 0.24.5 - Upgrade
Upgrade
popplerto a version that resolves this vulnerability.Fixed in 0.24.5
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7296?
CVE-2013-7296 is classified as a denial of service vulnerability leading to application crashes.
How do I fix CVE-2013-7296?
To fix CVE-2013-7296, upgrade Poppler to version 0.24.5 or later.
What software is affected by CVE-2013-7296?
CVE-2013-7296 affects Poppler versions prior to 0.24.5.
What type of attack does CVE-2013-7296 involve?
CVE-2013-7296 involves a context-dependent attack exploiting malformed PDF files.
Can CVE-2013-7296 be exploited remotely?
Yes, CVE-2013-7296 can be exploited remotely through maliciously crafted PDF files.