CVE-2020-23804: High severity poppler data vulnerability
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-23804?
CVE-2020-23804 is a vulnerability in poppler 0.89.0 that allows remote attackers to cause a denial of service through uncontrolled recursion in pdfinfo and pdftops.
How severe is CVE-2020-23804?
CVE-2020-23804 has a severity rating of high, with a CVSS score of 7.5.
How can remote attackers exploit CVE-2020-23804?
Remote attackers can exploit CVE-2020-23804 by sending crafted input to pdfinfo or pdftops, causing uncontrolled recursion and a denial of service.
Is there a fix available for CVE-2020-23804?
Yes, a fix for CVE-2020-23804 is available in poppler version 0.90.0 and later.
Where can I find more information about CVE-2020-23804?
More information about CVE-2020-23804 can be found at the following link: [https://gitlab.freedesktop.org/poppler/poppler/-/issues/936](https://gitlab.freedesktop.org/poppler/poppler/-/issues/936)