CVE-2019-10872: High severity Freedesktop poppler vulnerability
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-10872?
CVE-2019-10872 is a vulnerability in Poppler 0.74.0 that allows for a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
What is the severity of CVE-2019-10872?
The severity of CVE-2019-10872 is high with a CVSS score of 8.8.
How does CVE-2019-10872 impact Poppler?
CVE-2019-10872 allows an attacker to read beyond the allocated memory in Poppler, which can lead to potential information disclosure or crashes.
How can I fix CVE-2019-10872 in Poppler?
To fix CVE-2019-10872 in Poppler, update to the recommended version of the software provided by the vendor.
Where can I find more information about CVE-2019-10872?
You can find more information about CVE-2019-10872 at the following references: [Reference 1](http://www.securityfocus.com/bid/107862), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MAWV24KRXTFODLVT46RXI27XIQFX2QR/), [Reference 3](https://gitlab.freedesktop.org/poppler/poppler/issues/750).