CVE-2018-10768: Null Pointer Dereference
Last updated 25 August 2025
Other sources
Poppler is vulnerable to a NULL pointer dereference in the Annot.h:AnnotPath::getCoordsLength() function. An attacker could exploit this to cause a denial of service via crafted PDF.
Upstream Bug:
https://bugs.freedesktop.org/showbug.cgi?id=106408
— Red Hat
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10768?
CVE-2018-10768 is a vulnerability that allows for a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5, leading to a remote denial of service attack.
Which software is affected by CVE-2018-10768?
The affected software includes the Ubuntu package for Poppler 0.24.5.
How severe is CVE-2018-10768?
CVE-2018-10768 has a severity level of medium, with a CVSS score of 6.5.
How can I fix CVE-2018-10768?
To fix CVE-2018-10768, update your Ubuntu package for Poppler to version 0.24.5-2ubuntu4.11 or a later version that is not affected.
Where can I find more information about CVE-2018-10768?
You can find more information about CVE-2018-10768 at the following references: [Link 1](https://bugs.freedesktop.org/show_bug.cgi?id=106408), [Link 2](https://usn.ubuntu.com/3647-1/), [Link 3](https://access.redhat.com/errata/RHSA-2018:3140).