Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-37050

Опубликовано: 27 июл. 2022
Источник: redhat
CVSS3: 6.5

Описание

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

A vulnerability was found in poppler, where PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6popplerOut of support scope
Red Hat Enterprise Linux 7compat-poppler022Out of support scope
Red Hat Enterprise Linux 7popplerOut of support scope
Red Hat Enterprise Linux 8cups-containerNot affected
Red Hat Enterprise Linux 8gimp-flatpak-containerAffected
Red Hat Enterprise Linux 8gimp:flatpak/popplerAffected
Red Hat Enterprise Linux 8popplerAffected
Red Hat Enterprise Linux 9cups-containerNot affected
Red Hat Enterprise Linux 9inkscape:flatpak/popplerAffected
Red Hat Enterprise Linux 9libreoffice-flatpak-containerWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2234527poppler: abort in PDFDoc::savePageAs in PDFDoc.c

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

CVSS3: 6.5
nvd
больше 2 лет назад

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

CVSS3: 6.5
debian
больше 2 лет назад

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers t ...

CVSS3: 6.5
github
больше 2 лет назад

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость библиотеки для рендеринга PDF-файлов Poppler, связанная с неправильным завершением работы ресурса или его высвобождением, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3