A flaw was found in Poppler 0.72.0. A NULL pointer dereference in the XRef::getEntry class in XRef.cc file due to the mishandle of unallocated XRef entries. This allows remote attackers to cause a denial of service via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/692
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/mergerequests/143
A flaw was found in Poppler 0.72.0. A reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc file allows attackers to cause a denial of service due to the lack of a check for the dict data type.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/704
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/commit/de0c0b8324e776f0b851485e0fc9622fc35695b7
A flaw was found in Poppler 0.72.0. A reachable Object::getString assertion allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.
References: https://gitlab.freedesktop.org/poppler/poppler/issues/703
Upstream Patch: https://gitlab.freedesktop.org/poppler/poppler/mergerequests/146