CVE-2020-36024: Null Pointer Dereference
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-36024?
CVE-2020-36024 is a vulnerability in freedesktop poppler version 20.12.1 that allows remote attackers to cause a denial of service (DoS) through a crafted .pdf file.
How severe is CVE-2020-36024?
CVE-2020-36024 has a severity rating of 5.5 (Medium).
How do I fix CVE-2020-36024 in freedesktop poppler version 20.12.1?
To fix CVE-2020-36024 in freedesktop poppler version 20.12.1, you need to update to a patched version.
Where can I find more information about CVE-2020-36024?
You can find more information about CVE-2020-36024 at the following references: [Reference 1](https://gitlab.freedesktop.org/poppler/poppler/-/issues/1016), [Reference 2](https://lists.debian.org/debian-lts-announce/2023/08/msg00017.html), [Reference 3](https://launchpad.net/bugs/cve/CVE-2020-36024).
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-36024?
The Common Weakness Enumeration (CWE) ID for CVE-2020-36024 is 476.