CVE-2018-20481
Dashboard / Vulnerabilities / CVE-2018-20481
CVE-2018-20481
Summary:
Details: XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
References: https://lists.debian.org/debian-lts-announce/2020/07/msg00018.html, http://www.securityfocus.com/bid/106321, https://access.redhat.com/errata/RHSA-2019:2022, https://access.redhat.com/errata/RHSA-2019:2713, https://lists.debian.org/debian-lts-announce/2019/03/msg00008.html, https://usn.ubuntu.com/3865-1/, https://gitlab.freedesktop.org/poppler/poppler/issues/692, https://gitlab.freedesktop.org/poppler/poppler/merge_requests/143
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
