First published: Thu Jan 10 2019(Updated: )
A flaw was found in Poppler 0.72.0. A reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc file allows attackers to cause a denial of service due to the lack of a check for the dict data type. References: <a href="https://gitlab.freedesktop.org/poppler/poppler/issues/704">https://gitlab.freedesktop.org/poppler/poppler/issues/704</a> Upstream Patch: <a href="https://gitlab.freedesktop.org/poppler/poppler/commit/de0c0b8324e776f0b851485e0fc9622fc35695b7">https://gitlab.freedesktop.org/poppler/poppler/commit/de0c0b8324e776f0b851485e0fc9622fc35695b7</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Utilities |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1665263 is classified as a denial of service vulnerability.
To resolve REDHAT-BUG-1665263, update Poppler to the latest version that contains the fix.
REDHAT-BUG-1665263 affects Poppler version 0.72.0.
Yes, REDHAT-BUG-1665263 can potentially be exploited by attackers remotely.
REDHAT-BUG-1665263 represents a flaw in data type checking in the Poppler library.