Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12293

Опубликовано: 23 мая 2019
Источник: debian
EPSS Низкий

Описание

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
popplerfixed0.71.0-5package

Примечания

  • https://gitlab.freedesktop.org/poppler/poppler/issues/768

  • https://gitlab.freedesktop.org/poppler/poppler/commit/89a5367d49b2556a2635dbb6d48d6a6b182a2c6c

EPSS

Процентиль: 71%
0.00713
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

CVSS3: 6.6
redhat
около 6 лет назад

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

CVSS3: 8.8
nvd
около 6 лет назад

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

github
около 3 лет назад

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

CVSS3: 8.8
fstec
около 6 лет назад

Уязвимость функции JPXStream::init библиотеки для отображения PDF-файлов Poppler, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.00713
Низкий