Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-9545

Опубликовано: 01 мар. 2019
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.

РелизСтатусПримечание
bionic

ignored

end of standard support, was deferred
cosmic

ignored

end of life
devel

deferred

disco

ignored

end of life
eoan

ignored

end of life
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
esm-infra-legacy/xenial

deferred

esm-infra/bionic

deferred

esm-infra/focal

deferred

esm-infra/xenial

ignored

end of ESM support, was deferred

Показывать по

EPSS

Процентиль: 77%
0.01824
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

redhat
больше 7 лет назад

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.

CVSS3: 8.8
nvd
больше 7 лет назад

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.

CVSS3: 8.8
debian
больше 7 лет назад

An issue was discovered in Poppler 0.74.0. A recursive function call, ...

CVSS3: 8.8
github
больше 4 лет назад

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.

suse-cvrf
почти 3 года назад

Security update for poppler

EPSS

Процентиль: 77%
0.01824
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3