Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14494

Опубликовано: 11 июл. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

A divide-by-zero error was found in the way Poppler handled certain PDF files. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by an application linked to Poppler, would crash the application causing a denial of service.

Отчет

This flaw did not affect the versions of Poppler as shipped with Red Hat Enterprise Linux 5 and 6, as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5popplerNot affected
Red Hat Enterprise Linux 6popplerNot affected
Red Hat Enterprise Linux 7evinceFixedRHSA-2020:397729.09.2020
Red Hat Enterprise Linux 7popplerFixedRHSA-2020:397729.09.2020
Red Hat Enterprise Linux 8popplerFixedRHSA-2020:464304.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=1797453poppler: divide-by-zero in function SplashOutputDev::tilingPatternFill in SplashOutputDev.cc

EPSS

Процентиль: 83%
0.01969
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in Poppler through 0.78.0. There is a divide-b ...

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

oracle-oval
около 5 лет назад

ELSA-2020-4643: poppler security update (LOW)

EPSS

Процентиль: 83%
0.01969
Низкий

7.5 High

CVSS3