CVE-2018-20662: Input Validation
A flaw was found in Poppler 0.72.0. The PDFDoc::setup class in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/706
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/commit/9fd5ec0e6e5f763b190f2a55ceb5427cfe851d5f
Other sources
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20662.
What is the severity of CVE-2018-20662?
The severity of CVE-2018-20662 is medium with a CVSS score of 6.5.
How does CVE-2018-20662 impact Poppler?
CVE-2018-20662 allows attackers to cause a denial-of-service (application crash) in Poppler 0.72.0.
How can I fix the CVE-2018-20662 vulnerability?
To fix the CVE-2018-20662 vulnerability, update Poppler to version 0.71.0-5 or later.
Where can I find more information about CVE-2018-20662?
You can find more information about CVE-2018-20662 in the references provided: [GitLab commit](https://gitlab.freedesktop.org/poppler/poppler/commit/9fd5ec0e6e5f763b190f2a55ceb5427cfe851d5f), [GitLab issue](https://gitlab.freedesktop.org/poppler/poppler/issues/706), [Fedora mailing list](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZWP5XSUG6GNRI75NYKF53KIB2CZY6QQ6/).