Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6239

Опубликовано: 21 июн. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
popplerfixed24.08.0-2package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2293594

  • https://gitlab.freedesktop.org/poppler/poppler/-/issues/1489

  • Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/0554731052d1a97745cb179ab0d45620589dd9c4 (poppler-24.07.0)

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 60%
0.00403
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

CVSS3: 7.5
redhat
около 1 года назад

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

CVSS3: 7.5
nvd
12 месяцев назад

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

suse-cvrf
12 месяцев назад

Security update for poppler

suse-cvrf
12 месяцев назад

Security update for poppler

EPSS

Процентиль: 60%
0.00403
Низкий