First published: Tue Aug 22 2023(Updated: )
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/poppler | <20.09.0-1 | 20.09.0-1 |
ubuntu/poppler | <0.62.0-2ubuntu2.14+ | 0.62.0-2ubuntu2.14+ |
ubuntu/poppler | <0.86.1-0ubuntu1.4 | 0.86.1-0ubuntu1.4 |
ubuntu/poppler | <0.41.0-0ubuntu1.16+ | 0.41.0-0ubuntu1.16+ |
freedesktop poppler | =0.89.0 | |
Debian Debian Linux | =10.0 | |
=0.89.0 | ||
=10.0 | ||
debian/poppler | <=0.71.0-5 | 0.71.0-5+deb10u3 20.09.0-3.1+deb11u1 22.12.0-2 |
https://gitlab.freedesktop.org/poppler/poppler/-/commit/ec8a43c8df29fdd6f1228276160898ccd9401c92
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23804 is a vulnerability in poppler 0.89.0 that allows remote attackers to cause a denial of service through uncontrolled recursion in pdfinfo and pdftops.
CVE-2020-23804 has a severity rating of high, with a CVSS score of 7.5.
Remote attackers can exploit CVE-2020-23804 by sending crafted input to pdfinfo or pdftops, causing uncontrolled recursion and a denial of service.
Yes, a fix for CVE-2020-23804 is available in poppler version 0.90.0 and later.
More information about CVE-2020-23804 can be found at the following link: [https://gitlab.freedesktop.org/poppler/poppler/-/issues/936](https://gitlab.freedesktop.org/poppler/poppler/-/issues/936)