CVE-2019-9631: Critical severity Freedesktop poppler vulnerability
Last updated 25 August 2025
Other sources
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsamplerowboxfilter function.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-9631?
CVE-2019-9631 is a heap-based buffer over-read vulnerability in Poppler 0.74.0.
How can the CVE-2019-9631 vulnerability affect me?
If you are using Poppler 0.74.0 or affected software, an attacker could exploit this vulnerability to cause a denial-of-service condition or possibly execute arbitrary code on your system.
What is the severity of CVE-2019-9631?
CVE-2019-9631 has a severity rating of 9.8 (Critical).
How do I fix CVE-2019-9631?
To fix CVE-2019-9631, update Poppler to version 0.71.0 or later, depending on the operating system you are using. For Debian, the remedy version is 0.71.0-5 or later. For Ubuntu, the remedy versions are 0.62.0-2ubuntu2.9, 0.68.0-0ubuntu1.7, 0.74.0-0ubuntu1.2, or later.
Where can I find more information about CVE-2019-9631?
You can find more information about CVE-2019-9631 at the following references: [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9631), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-4042-1), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-9631).