CVE-2019-12293: High severity Freedesktop poppler vulnerability
An issue was discovered in Poppler 0.76.1. There is a heap-based buffer over-read in the function JPXStream::init in JPEG2000Stream.cc.
Upstream issue: https://gitlab.freedesktop.org/poppler/poppler/issues/768
Other sources
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Poppler vulnerability?
The vulnerability ID for this Poppler vulnerability is CVE-2019-12293.
What is the severity of CVE-2019-12293?
The severity of CVE-2019-12293 is high (8.8).
Which software versions are affected by CVE-2019-12293?
Poppler versions up to and including 0.76.1 are affected by CVE-2019-12293.
How can I fix the CVE-2019-12293 vulnerability?
To fix the CVE-2019-12293 vulnerability, update Poppler to version 0.77.0 or later.
Where can I find more information about CVE-2019-12293?
You can find more information about CVE-2019-12293 at the following references: [CVE-2019-12293](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12293), [Ubuntu Security Notice USN-4042-1](https://ubuntu.com/security/notices/USN-4042-1), [NVD CVE-2019-12293](https://nvd.nist.gov/vuln/detail/CVE-2019-12293).