Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9959

Опубликовано: 23 июл. 2019
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5popplerOut of support scope
Red Hat Enterprise Linux 6popplerOut of support scope
Red Hat Enterprise Linux 7evinceFixedRHSA-2020:107431.03.2020
Red Hat Enterprise Linux 7popplerFixedRHSA-2020:107431.03.2020
Red Hat Enterprise Linux 8popplerFixedRHSA-2019:271312.09.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1732340poppler: integer overflow in JPXStream::init function leading to memory consumption

EPSS

Процентиль: 64%
0.00481
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

CVSS3: 6.5
nvd
почти 6 лет назад

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

CVSS3: 6.5
debian
почти 6 лет назад

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't che ...

CVSS3: 6.5
github
около 3 лет назад

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

CVSS3: 6.5
fstec
почти 6 лет назад

Уязвимость функции JPXStream::init библиотеки для отображения PDF-файлов Poppler, связанная с целочисленным переполнением значения, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 64%
0.00481
Низкий

6.2 Medium

CVSS3