First published: Fri Mar 08 2019(Updated: )
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. Reference: <a href="https://gitlab.freedesktop.org/poppler/poppler/issues/736">https://gitlab.freedesktop.org/poppler/poppler/issues/736</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Utilities |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1686802 is considered to be high due to the potential for a heap-based buffer over-read.
To fix REDHAT-BUG-1686802, upgrade to the patched version of Poppler that addresses this vulnerability.
Poppler version 0.74.0 is affected by the vulnerability identified in REDHAT-BUG-1686802.
The vulnerability REDHAT-BUG-1686802 is caused by a heap-based buffer over-read in the downsample_row_box_filter function within the CairoRescaleBox.cc file.
Exploiting REDHAT-BUG-1686802 can lead to information disclosure and potential system compromise due to buffer over-read vulnerabilities.