REDHAT-BUG-1686802: Low severity poppler data vulnerability
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsamplerowboxfilter function.
Reference: https://gitlab.freedesktop.org/poppler/poppler/issues/736
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1686802?
The severity of REDHAT-BUG-1686802 is considered to be high due to the potential for a heap-based buffer over-read.
How do I fix REDHAT-BUG-1686802?
To fix REDHAT-BUG-1686802, upgrade to the patched version of Poppler that addresses this vulnerability.
Which versions of Poppler are affected by REDHAT-BUG-1686802?
Poppler version 0.74.0 is affected by the vulnerability identified in REDHAT-BUG-1686802.
What causes the vulnerability REDHAT-BUG-1686802?
The vulnerability REDHAT-BUG-1686802 is caused by a heap-based buffer over-read in the downsample_row_box_filter function within the CairoRescaleBox.cc file.
What are the potential impacts of exploiting REDHAT-BUG-1686802?
Exploiting REDHAT-BUG-1686802 can lead to information disclosure and potential system compromise due to buffer over-read vulnerabilities.