REDHAT-BUG-1576169: Null Pointer Dereference
Published May 9, 2018
·Updated
Poppler is vulnerable to a NULL pointer dereference in the Annot.h:AnnotPath::getCoordsLength() function. An attacker could exploit this to cause a denial of service via crafted PDF.
Upstream Bug:
https://bugs.freedesktop.org/showbug.cgi?id=106408
Affected Software
1 affected component
Poppler Poppler
Event History
May 9, 2018
Data Sourced
via Red Hat·03:49 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1576169?
The severity of REDHAT-BUG-1576169 is high due to its potential to cause a denial of service.
2
How do I fix REDHAT-BUG-1576169?
To fix REDHAT-BUG-1576169, update to the latest version of the Poppler library that addresses this vulnerability.
3
What type of attack does REDHAT-BUG-1576169 facilitate?
REDHAT-BUG-1576169 can be exploited to facilitate a denial of service attack via specially crafted PDF files.
4
Which software is affected by REDHAT-BUG-1576169?
REDHAT-BUG-1576169 affects the Poppler PDF rendering library.
5
Is there any known workaround for REDHAT-BUG-1576169?
There are no documented workarounds for REDHAT-BUG-1576169; applying the patch is recommended.