CVE-2018-20481: Null Pointer Dereference
A flaw was found in Poppler 0.72.0. A NULL pointer dereference in the XRef::getEntry class in XRef.cc file due to the mishandle of unallocated XRef entries. This allows remote attackers to cause a denial of service via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/692
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/mergerequests/143
Other sources
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-20481?
CVE-2018-20481 is a vulnerability in the Poppler PDF library that allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document.
How does CVE-2018-20481 affect the affected software?
CVE-2018-20481 affects the Poppler package version 0.72.0 and prior on Debian and Ubuntu Linux distributions.
What is the severity of CVE-2018-20481?
CVE-2018-20481 has a severity rating of 6.5 (medium).
How can I fix the CVE-2018-20481 vulnerability?
To fix the CVE-2018-20481 vulnerability, you should update the Poppler package to version 0.71.0-5 or later on Debian, or version 0.41.0-0ubuntu1.11 or later on Ubuntu.
Where can I find more information about CVE-2018-20481?
More information about CVE-2018-20481 can be found at the following references: [http://www.securityfocus.com/bid/106321](http://www.securityfocus.com/bid/106321) and [https://access.redhat.com/errata/RHSA-2019:2022](https://access.redhat.com/errata/RHSA-2019:2022)