REDHAT-BUG-495907: Integer Overflow
An integer overflow was found in poppler's SplashBitmap::SplashBitmap method. A malicious PDF file could cause poppler to execute with permissions of the user calling the library.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting this flaw.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-495907?
The severity of REDHAT-BUG-495907 is considered critical due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-495907?
To fix REDHAT-BUG-495907, you should update the Poppler library to the latest patched version.
What platforms are affected by REDHAT-BUG-495907?
REDHAT-BUG-495907 affects systems utilizing the Poppler library for PDF processing.
What is the impact of exploiting REDHAT-BUG-495907?
Exploiting REDHAT-BUG-495907 allows an attacker to execute code with the permissions of the user running the affected application.
What should I do if I suspect my system is affected by REDHAT-BUG-495907?
If you suspect your system is affected by REDHAT-BUG-495907, it is advisable to immediately update your Poppler library and assess any potential breaches.