First published: Thu Aug 01 2019(Updated: )
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/poppler | <0.62.0-2ubuntu2.10 | 0.62.0-2ubuntu2.10 |
ubuntu/poppler | <0.74.0-0ubuntu1.3 | 0.74.0-0ubuntu1.3 |
debian/poppler | 20.09.0-3.1+deb11u1 22.12.0-2 24.08.0-2 | |
freedesktop poppler | <=0.78.0 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 |
https://gitlab.freedesktop.org/poppler/poppler/commit/b224e2f5739fe61de9fa69955d016725b2a4b78d
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14494 is a vulnerability discovered in Poppler through 0.78.0 that allows for a divide-by-zero error in the SplashOutputDev::tilingPatternFill function.
The severity of CVE-2019-14494 is high, with a severity value of 7.5.
CVE-2019-14494 affects the Poppler software versions 0.62.0-2ubuntu2.10, 0.74.0-0ubuntu1.3, and 0.78.0.
To fix CVE-2019-14494, update the affected software to version 0.62.0-2ubuntu2.10, 0.74.0-0ubuntu1.3, or 0.78.0.
More information about CVE-2019-14494 can be found at the following references: [link1], [link2], [link3].