First published: Tue Nov 13 2018(Updated: )
An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path. References: <a href="https://gitlab.freedesktop.org/poppler/poppler/issues/660">https://gitlab.freedesktop.org/poppler/poppler/issues/660</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Utilities |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1649450 is categorized as denial of service due to a NULL pointer dereference.
To fix REDHAT-BUG-1649450, it is recommended to upgrade to a later version of Poppler that addresses this vulnerability.
REDHAT-BUG-1649450 affects Poppler version 0.71.0.
The impact of REDHAT-BUG-1649450 is a potential denial of service that may occur when an embedded file's filename is not validated.
Currently, there is no documented workaround for REDHAT-BUG-1649450; the best action is to upgrade the software.