First published: Tue Nov 13 2018(Updated: )
An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts. References: <a href="https://gitlab.freedesktop.org/poppler/poppler/issues/661">https://gitlab.freedesktop.org/poppler/poppler/issues/661</a> Upstream Patch: <a href="https://gitlab.freedesktop.org/poppler/poppler/merge_requests/109">https://gitlab.freedesktop.org/poppler/poppler/merge_requests/109</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Utilities |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1649440 is considered high due to the potential for denial of service.
To fix REDHAT-BUG-1649440, update Poppler to the latest version that addresses this vulnerability.
The vulnerability in REDHAT-BUG-1649440 is caused by an out-of-bounds read in the Poppler library when handling embedded files.
Poppler version 0.71.0 is affected by the issue described in REDHAT-BUG-1649440.
Yes, REDHAT-BUG-1649440 can be exploited remotely, allowing attackers to trigger denial of service.