CVE-2023-34872: Medium severity poppler data vulnerability
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-34872?
CVE-2023-34872 is a vulnerability in Outline.cc for Poppler prior to 23.06.0 that allows a remote attacker to cause a Denial of Service (DoS) via a crafted PDF file in OutlineItem::open.
How does CVE-2023-34872 impact the affected software?
CVE-2023-34872 has a severity rating of medium (5.5) and can cause a Denial of Service (DoS) (crash) in the affected software.
Which versions of Poppler are affected by CVE-2023-34872?
Poppler versions prior to 23.06.0 are affected by CVE-2023-34872.
How can I fix CVE-2023-34872?
To fix CVE-2023-34872, update Poppler to version 23.06.0 or later.
Where can I find more information about CVE-2023-34872?
More information about CVE-2023-34872 can be found at the following references: [Link 1](https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe), [Link 2](https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399), [Link 3](https://launchpad.net/bugs/cve/CVE-2023-34872).