CVE-2019-9959: Integer Overflow
Published Jul 22, 2019
·Updated
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.
Affected Software
18 affected componentsFixes available
redhat/poppler<0.79
0.79
Freedesktop poppler<=0.78.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=29
Fedoraproject Fedora=30
redhat Enterprise Linux=8.0
redhat Enterprise Linux Eus=8.1
redhat Enterprise Linux Eus=8.2
redhat Enterprise Linux Eus=8.4
redhat Enterprise Linux Eus=8.6
redhat Enterprise Linux Server Aus=8.2
redhat Enterprise Linux Server Aus=8.4
redhat Enterprise Linux Server Aus=8.6
redhat Enterprise Linux Server Tus=8.2
redhat Enterprise Linux Server Tus=8.4
redhat Enterprise Linux Server Tus=8.6
Event History
Jul 22, 2019
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-9959.
2
What is the severity rating of CVE-2019-9959?
CVE-2019-9959 has a severity rating of 6.5 (medium).
3
How does the vulnerability in Poppler occur?
The vulnerability in Poppler occurs due to the JPXStream::init function not checking for negative values of stream length.
4
What is the impact of the CVE-2019-9959 vulnerability?
The CVE-2019-9959 vulnerability allows an attacker to allocate a large memory chunk on the heap, leading to an integer overflow.
5
Is there a fix available for CVE-2019-9959?
Yes, a fix is available for CVE-2019-9959 in version 0.79 of Poppler.