REDHAT-BUG-1696636: Medium severity poppler data vulnerability
Published Apr 5, 2019
·Updated
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
Reference: https://gitlab.freedesktop.org/poppler/poppler/issues/751
Affected Software
1 affected component
Poppler Poppler
Event History
Apr 5, 2019
Data Sourced
via Red Hat·10:30 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1696636?
The severity of REDHAT-BUG-1696636 is classified as moderate due to the potential for a heap-based buffer over-read.
2
How do I fix REDHAT-BUG-1696636?
To fix REDHAT-BUG-1696636, you should upgrade to a version of Poppler that addresses this buffer over-read vulnerability.
3
What are the potential impacts of REDHAT-BUG-1696636?
The potential impacts of REDHAT-BUG-1696636 include possible information disclosure or application crashes.
4
Is REDHAT-BUG-1696636 actively being exploited?
As of now, there are no known active exploits specifically targeting REDHAT-BUG-1696636.
5
Which version of Poppler is affected by REDHAT-BUG-1696636?
REDHAT-BUG-1696636 affects Poppler version 0.74.0.