Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f98-v8mx-8cr7

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

Ссылки

EPSS

Процентиль: 91%
0.06879
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

redhat
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

nvd
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

debian
около 17 лет назад

The CairoFont::create function in CairoFontEngine.cc in Poppler, possi ...

oracle-oval
около 17 лет назад

ELSA-2008-0239: poppler security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06879
Низкий

Дефекты

CWE-20