CVE-2018-19060: Null Pointer Dereference
An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-19060?
CVE-2018-19060 is a vulnerability discovered in Poppler 0.71.0 that allows for a NULL pointer dereference in goo/GooString.h, leading to denial of service.
How does CVE-2018-19060 affect the software?
CVE-2018-19060 affects Poppler 0.71.0 as well as Canonical Ubuntu Linux versions 14.04, 16.04, 18.04, and 18.10.
What is the severity of CVE-2018-19060?
CVE-2018-19060 has a severity value of 6.5, which is considered medium.
How can CVE-2018-19060 be fixed?
To fix CVE-2018-19060, you can update to the latest version of Poppler or apply the provided patches for Ubuntu and Debian.
Where can I find more information about CVE-2018-19060?
You can find more information about CVE-2018-19060 in the references provided: GitLab, Ubuntu Security Notice, and Red Hat.