REDHAT-BUG-1649440: Low severity poppler data vulnerability
An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/661
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/mergerequests/109
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1649440?
The severity of REDHAT-BUG-1649440 is considered high due to the potential for denial of service.
How do I fix REDHAT-BUG-1649440?
To fix REDHAT-BUG-1649440, update Poppler to the latest version that addresses this vulnerability.
What causes the vulnerability in REDHAT-BUG-1649440?
The vulnerability in REDHAT-BUG-1649440 is caused by an out-of-bounds read in the Poppler library when handling embedded files.
Which versions of Poppler are affected by REDHAT-BUG-1649440?
Poppler version 0.71.0 is affected by the issue described in REDHAT-BUG-1649440.
Can REDHAT-BUG-1649440 be exploited remotely?
Yes, REDHAT-BUG-1649440 can be exploited remotely, allowing attackers to trigger denial of service.