First published: Fri Apr 05 2019(Updated: )
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
freedesktop poppler | =0.74.0 | |
debian/poppler | 20.09.0-3.1+deb11u1 22.12.0-2 24.08.0-4 |
https://gitlab.freedesktop.org/poppler/poppler/commit/6a1580e84f492b5671d23be98192267bb73de250
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10872 is a vulnerability in Poppler 0.74.0 that allows for a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
The severity of CVE-2019-10872 is high with a CVSS score of 8.8.
CVE-2019-10872 allows an attacker to read beyond the allocated memory in Poppler, which can lead to potential information disclosure or crashes.
To fix CVE-2019-10872 in Poppler, update to the recommended version of the software provided by the vendor.
You can find more information about CVE-2019-10872 at the following references: [Reference 1](http://www.securityfocus.com/bid/107862), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MAWV24KRXTFODLVT46RXI27XIQFX2QR/), [Reference 3](https://gitlab.freedesktop.org/poppler/poppler/issues/750).