Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19060

Опубликовано: 06 нояб. 2018
Источник: redhat
CVSS3: 3.3

Описание

An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.

Отчет

This issue affects the versions of poppler as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5popplerNot affected
Red Hat Enterprise Linux 6popplerNot affected
Red Hat Enterprise Linux 8popplerNot affected
Red Hat Enterprise Linux 7evinceFixedRHSA-2019:202206.08.2019
Red Hat Enterprise Linux 7okularFixedRHSA-2019:202206.08.2019
Red Hat Enterprise Linux 7popplerFixedRHSA-2019:202206.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1649450poppler: pdfdetach utility does not validate save paths

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.

CVSS3: 6.5
nvd
больше 6 лет назад

An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.

CVSS3: 6.5
debian
больше 6 лет назад

An issue was discovered in Poppler 0.71.0. There is a NULL pointer der ...

CVSS3: 6.5
github
около 3 лет назад

An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.

oracle-oval
почти 6 лет назад

ELSA-2019-2022: poppler security, bug fix, and enhancement update (MODERATE)

3.3 Low

CVSS3