CVE-2022-37050: Medium severity poppler data vulnerability
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-37050?
CVE-2022-37050 is a vulnerability in the Poppler software library that allows attackers to cause a denial-of-service by crafting a malicious PDF file.
What is the severity of CVE-2022-37050?
CVE-2022-37050 has a severity rating of medium with a CVSS score of 6.5.
How does CVE-2022-37050 affect Poppler?
CVE-2022-37050 affects Poppler version 22.07.0.
How can I fix CVE-2022-37050?
To fix CVE-2022-37050, users should update to a patched version of Poppler, such as a version later than 22.07.0.
Where can I find more information about CVE-2022-37050?
More information about CVE-2022-37050 can be found in the references provided: [Reference 1](https://gitlab.freedesktop.org/poppler/poppler/-/commit/dcd5bd8238ea448addd102ff045badd0aca1b990), [Reference 2](https://gitlab.freedesktop.org/poppler/poppler/-/issues/1274)