Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20551

Опубликовано: 28 дек. 2018
Источник: debian

Описание

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
popplerfixed0.71.0-4package
popplerignoredstretchpackage
popplernot-affectedjessiepackage

Примечания

  • https://gitlab.freedesktop.org/poppler/poppler/issues/703

  • https://gitlab.freedesktop.org/poppler/poppler/commit/7f87dc10b6adccd6d1b977a28b064add254aa2da

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

CVSS3: 3.3
redhat
почти 7 лет назад

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

CVSS3: 6.5
nvd
почти 7 лет назад

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

CVSS3: 6.5
github
больше 3 лет назад

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

CVSS3: 4.3
fstec
почти 7 лет назад

Уязвимость библиотеки для отображения PDF-файлов Poppler, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании