CVE-2022-27337: Medium severity poppler data vulnerability
Published May 5, 2022
·Updated
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Affected Software
7 affected componentsFixes available
debian/poppler<=0.71.0-5
0.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
ubuntu/poppler<22.02.0-2ubuntu0.2
22.02.0-2ubuntu0.2
ubuntu/poppler<0.86.1-0ubuntu1.2
0.86.1-0ubuntu1.2
Freedesktop poppler=22.03.0
Fedoraproject Fedora=36
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
May 5, 2022
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
May 7, 2022
Data Sourced
03:06 PM
SeverityAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:07 AM
Description
Frequently Asked Questions
1
What is CVE-2022-27337?
CVE-2022-27337 is a logic error vulnerability in the Hints::Hints function of Poppler v22.03.0 that can be exploited by attackers to cause a Denial of Service (DoS) through a specially crafted PDF file.
2
How does CVE-2022-27337 affect Poppler?
CVE-2022-27337 affects Poppler version 22.03.0.
3
What is the severity of CVE-2022-27337?
The severity of CVE-2022-27337 is high with a severity value of 7.
4
How can I fix CVE-2022-27337 on Ubuntu?
To fix CVE-2022-27337 on Ubuntu, update the poppler package to version 22.02.0-2ubuntu0.2.
5
How can I fix CVE-2022-27337 on Debian?
To fix CVE-2022-27337 on Debian, update the poppler package to a version between 0.71.0-5+deb10u2 and 0.71.0-5.