USN-6273-1: poppler vulnerabilities
Jieyong Ma discovered that poppler incorrectly handled certain malformed PDF files. A remote attacker could possibly use this issue to cause poppler to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-27337) It was discovered that poppler incorrectly handled certain malformed PDF files. A remote attacker could possibly use this issue to cause poppler to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2023-34872)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2022-27337.
How does this vulnerability affect Ubuntu 20.04 LTS and Ubuntu 22.04 LTS?
This vulnerability affects Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
What is the severity of CVE-2022-27337?
The severity of CVE-2022-27337 is not mentioned in the advisory.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by using certain malformed PDF files to cause the poppler library to crash, resulting in a denial of service.
How can I fix this vulnerability?
To fix this vulnerability, update the libpoppler126 package to version 22.12.0-2ubuntu1.1 (for Ubuntu 22.04 LTS and Ubuntu 23.04) or update the libpoppler97 package to version 0.86.1-0ubuntu1.2 (for Ubuntu 20.04 LTS).