First published: Wed Jul 18 2018(Updated: )
An out-of-bounds read flaw was found in the Poppler library as demonstrated by pdfunite. This may result in a denial of service or other undefined behavior. This flaw may be exploitable when a victim opens a specially crafted PDF file. Upstream Patch: <a href="https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5ee">https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5ee</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
freedesktop poppler | <=0.62.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Debian Debian Linux | =8.0 | |
Redhat Ansible Tower | =3.3.0 | |
Redhat Openshift Container Platform | =3.11 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
redhat/poppler | <0.67.0 | 0.67.0 |
ubuntu/poppler | <0.62.0-2ubuntu2.2 | 0.62.0-2ubuntu2.2 |
ubuntu/poppler | <0.24.5-2ubuntu4.12 | 0.24.5-2ubuntu4.12 |
ubuntu/poppler | <0.41.0-0ubuntu1.8 | 0.41.0-0ubuntu1.8 |
debian/poppler | 20.09.0-3.1+deb11u1 22.12.0-2 24.08.0-2 |
https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5ee
https://cgit.freedesktop.org/poppler/poppler/patch/?id=004e3c10df0abda214f0c293f9e269fdd979c5ee
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13988 is an out of bounds read vulnerability in Poppler through 0.62, which can result in memory corruption and denial of service.
CVE-2018-13988 affects Poppler versions 0.41.0-0ubuntu1.8, 0.62.0-2ubuntu2.2, 0.24.5-2ubuntu4.12, 0.67.0, 0.71.0-5, 0.71.0-5+deb10u3, 20.09.0-3.1+deb11u1, and 22.12.0-2.
CVE-2018-13988 has a severity rating of 6.5 (medium).
CVE-2018-13988 can be exploited when a victim opens a specially crafted PDF file.
Yes, remedy packages are available for the affected versions of Poppler. Please refer to the official sources for the specific fixes.