CVE-2018-19149: Null Pointer Dereference
An issue was found in Poppler before 0.70.0. A NULL pointer dereference in popplerattachmentnew when called from popplerannotfileattachmentgetattachment.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/664
Other sources
Poppler before 0.70.0 has a NULL pointer dereference in popplerattachmentnew when called from popplerannotfileattachmentgetattachment.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-19149?
CVE-2018-19149 is a vulnerability in Poppler before 0.70.0 that allows for a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
How severe is CVE-2018-19149?
CVE-2018-19149 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2018-19149?
To fix CVE-2018-19149, update to Poppler version 0.71.0-5 or later.
Where can I find more information about CVE-2018-19149?
You can find more information about CVE-2018-19149 on the GitLab page for Poppler, the SecurityFocus website, and the Ubuntu Security Notice 3837-1.
What is the Common Weakness Enumeration (CWE) for CVE-2018-19149?
The Common Weakness Enumeration (CWE) for CVE-2018-19149 is CWE-476, which is a vulnerability related to NULL Pointer Dereference.