CVE-2018-13988: Medium severity Freedesktop poppler vulnerability
An out-of-bounds read flaw was found in the Poppler library as demonstrated by pdfunite. This may result in a denial of service or other undefined behavior. This flaw may be exploitable when a victim opens a specially crafted PDF file.
Upstream Patch: https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5ee
Other sources
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-13988?
CVE-2018-13988 is an out of bounds read vulnerability in Poppler through 0.62, which can result in memory corruption and denial of service.
Which software is affected by CVE-2018-13988?
CVE-2018-13988 affects Poppler versions 0.41.0-0ubuntu1.8, 0.62.0-2ubuntu2.2, 0.24.5-2ubuntu4.12, 0.67.0, 0.71.0-5, 0.71.0-5+deb10u3, 20.09.0-3.1+deb11u1, and 22.12.0-2.
What is the severity of CVE-2018-13988?
CVE-2018-13988 has a severity rating of 6.5 (medium).
How can CVE-2018-13988 be exploited?
CVE-2018-13988 can be exploited when a victim opens a specially crafted PDF file.
Is there a fix available for CVE-2018-13988?
Yes, remedy packages are available for the affected versions of Poppler. Please refer to the official sources for the specific fixes.