REDHAT-BUG-1672419: Medium severity poppler data vulnerability
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.
References: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12797 https://gitlab.freedesktop.org/poppler/poppler/issues/717
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/mergerequests/172
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1672419?
The severity of REDHAT-BUG-1672419 is classified as high due to the potential for remote denial of service and application crashes.
How do I fix REDHAT-BUG-1672419?
To fix REDHAT-BUG-1672419, update to a patched version of Poppler that addresses the heap-based buffer over-read vulnerability.
What impact does REDHAT-BUG-1672419 have on affected systems?
The impact of REDHAT-BUG-1672419 on affected systems includes potential application crashes and denial of service due to exploitation of the vulnerability.
Who is affected by REDHAT-BUG-1672419?
Users of Poppler, particularly those handling PDF documents, are affected by REDHAT-BUG-1672419.
What version of Poppler is affected by REDHAT-BUG-1672419?
Poppler version 0.73.0 is specifically identified as affected by REDHAT-BUG-1672419.