CVE-2018-21009: Integer Overflow
A vulnerability was found in Poppler before 0.76.0 has an integer overflow in Parser::makeStream in Parser.cc.
Reference: https://gitlab.freedesktop.org/poppler/poppler/commit/0868c499a9f5f37f8df5c9fef03c37496b40fc8a
Other sources
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-21009?
CVE-2018-21009 is a vulnerability in Poppler before version 0.66.0 that allows an integer overflow in Parser::makeStream in Parser.cc.
How severe is CVE-2018-21009?
CVE-2018-21009 has a severity rating of 8.8 out of 10, indicating a high severity.
What software is affected by CVE-2018-21009?
Poppler before version 0.76.0 and freedesktop poppler up to version 0.76.0 are affected by CVE-2018-21009.
How can I fix CVE-2018-21009?
To fix CVE-2018-21009, update Poppler to version 0.76.0 or later.
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-21009?
CVE-2018-21009 is associated with CWE-190, which is the numeric errors weakness.