CVE-2022-37051: Medium severity poppler data vulnerability
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-37051?
CVE-2022-37051 is a vulnerability in Poppler 22.07.0 that allows for denial of service due to a reachable abort in the main function of pdfunite.cc.
How severe is CVE-2022-37051?
CVE-2022-37051 has a severity of 6.5 (medium).
How does CVE-2022-37051 affect Poppler 22.07.0?
CVE-2022-37051 affects Poppler 22.07.0 by causing denial of service through a reachable abort in the main function of pdfunite.cc.
How can I fix the vulnerability CVE-2022-37051?
To fix CVE-2022-37051, it is recommended to update to a version of Poppler that includes the patch provided by the upstream vendor.
Where can I find more information about CVE-2022-37051?
More information about CVE-2022-37051 can be found in the references provided: [Reference 1](https://gitlab.freedesktop.org/poppler/poppler/-/commit/4631115647c1e4f0482ffe0491c2f38d2231337b) [Reference 2](https://gitlab.freedesktop.org/poppler/poppler/-/issues/1276)