Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-38349

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

A flaw was found in the Poppler package. This issue occurs due to a reachable assertion in Object.h. By using a specially crafted file, an attacker could cause a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6popplerOut of support scope
Red Hat Enterprise Linux 7compat-poppler022Out of support scope
Red Hat Enterprise Linux 7popplerOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/popplerNot affected
Red Hat Enterprise Linux 8inkscape:flatpak/popplerNot affected
Red Hat Enterprise Linux 8libreoffice:flatpak/popplerNot affected
Red Hat Enterprise Linux 8popplerNot affected
Red Hat Enterprise Linux 9inkscape:flatpak/popplerNot affected
Red Hat Enterprise Linux 9libreoffice:flatpak/popplerNot affected
Red Hat Enterprise Linux 9popplerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2251630poppler: Reachable assertion in Object.h

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

CVSS3: 6.5
nvd
больше 2 лет назад

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

CVSS3: 6.5
debian
больше 2 лет назад

An issue was discovered in Poppler 22.08.0. There is a reachable asser ...

CVSS3: 6.5
github
больше 2 лет назад

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость функции PDFDoc::replacePageDict (PDFDoc.cc) библиотеки для рендеринга PDF-файлов Poppler, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3