Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27778

Опубликовано: 03 дек. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
Версия до 0.76.0 (исключая)
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00283
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-824
CWE-824

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

CVSS3: 7.5
redhat
почти 7 лет назад

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

CVSS3: 7.5
debian
около 5 лет назад

A flaw was found in Poppler in the way certain PDF files were converte ...

rocky
больше 4 лет назад

Moderate: poppler and evince security, bug fix, and enhancement update

CVSS3: 7.5
github
больше 3 лет назад

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

EPSS

Процентиль: 51%
0.00283
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-824
CWE-824