CVE-2018-18897: Medium severity poppler data vulnerability
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-18897?
CVE-2018-18897 is a vulnerability in Poppler 0.71.0 that causes a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc.
How severe is CVE-2018-18897?
CVE-2018-18897 has a severity rating of 6.5 (Medium).
Which software versions are affected by CVE-2018-18897?
Poppler 0.71.0, Debian Linux 10.0, Ubuntu Linux 16.04, Ubuntu Linux 18.04, Ubuntu Linux 18.10, Ubuntu Linux 19.04, Redhat Enterprise Linux 8.0, Redhat Enterprise Linux Desktop 7.0, Redhat Enterprise Linux Eus 8.1, Redhat Enterprise Linux Eus 8.2, Redhat Enterprise Linux Eus 8.4, Redhat Enterprise Linux Eus 8.6, Redhat Enterprise Linux Server 7.0, Redhat Enterprise Linux Server Aus 8.2, Redhat Enterprise Linux Server Aus 8.4, Redhat Enterprise Linux Server Aus 8.6, Redhat Enterprise Linux Server Tus 8.2, Redhat Enterprise Linux Server Tus 8.4, Redhat Enterprise Linux Server Tus 8.6, Redhat Enterprise Linux Workstation 7.0.
What is the remedy for CVE-2018-18897?
The remedy for CVE-2018-18897 is to update to version 0.62.0-2ubuntu2.9 (Ubuntu), version 0.68.0-0ubuntu1.7 (Ubuntu), version 0.41.0-0ubuntu1.14 (Ubuntu), version 0.71.0-5+deb10u3, 20.09.0-3.1+deb11u1, or 22.12.0-2 (Debian), or apply the necessary patches.
Where can I find more information about CVE-2018-18897?
You can find more information about CVE-2018-18897 at the following references: [Reference 1](https://gitlab.freedesktop.org/poppler/poppler/issues/654), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1646550), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1646549).