CVE-2018-16646: Medium severity Freedesktop poppler vulnerability
A flaw was found in Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
References: https://bugzilla.redhat.com/showbug.cgi?id=1622951
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16646?
CVE-2018-16646 is a vulnerability in Poppler 0.68.0 that allows for infinite recursion and can be exploited for a DoS attack.
How severe is CVE-2018-16646?
CVE-2018-16646 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2018-16646?
CVE-2018-16646 affects Poppler versions 0.41.0-0ubuntu1.9, 0.62.0-2ubuntu2.4, 0.68.0-0ubuntu1.2, and 0.24.5-2ubuntu4.13.
How can CVE-2018-16646 be fixed?
To fix CVE-2018-16646, users should update their Poppler software to versions that have the remedy as specified in the affected software list.
Where can I find more information about CVE-2018-16646?
More information about CVE-2018-16646 can be found at the following references: - Red Hat: https://access.redhat.com/errata/RHSA-2019:2022 - Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1622951 - Debian: https://lists.debian.org/debian-lts-announce/2018/10/msg00024.html