CVE-2019-7310: High severity Freedesktop poppler vulnerability
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-7310?
CVE-2019-7310 is a vulnerability in the Poppler library that allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
What is the severity of CVE-2019-7310?
The severity of CVE-2019-7310 is high, with a CVSS score of 7.8.
Which software versions are affected by CVE-2019-7310?
The affected software versions include Poppler 0.71.0-5, 0.71.0-5+deb10u3, 20.09.0-3.1+deb11u1, 22.12.0-2, and various versions of Ubuntu and Debian distributions.
How can I fix CVE-2019-7310?
To fix CVE-2019-7310, update to the latest version of Poppler and apply any available patches provided by your operating system or software vendor.
Where can I find more information about CVE-2019-7310?
You can find more information about CVE-2019-7310 in the references section, which includes links to security advisories and related resources.