CVE-2022-38349: Medium severity poppler data vulnerability
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Poppler 22.08.0?
The vulnerability ID for this issue in Poppler 22.08.0 is CVE-2022-38349.
What is the severity of CVE-2022-38349?
The severity of CVE-2022-38349 is medium, with a CVSS score of 6.5.
What is the description of CVE-2022-38349?
CVE-2022-38349 is an issue in Poppler 22.08.0 that involves a reachable assertion in Object.h, leading to denial of service due to a lack of stream check.
How does CVE-2022-38349 affect Poppler 22.08.0?
CVE-2022-38349 affects Poppler 22.08.0 by introducing a reachable assertion vulnerability that can be exploited to cause denial of service.
Is there a fix available for CVE-2022-38349?
Yes, there is a fix available for CVE-2022-38349. You can refer to the provided GitLab commit and issue links for more information.