ZeroHour

CVE-2018-10768

PoC
CVSS 3.0
6.5 medium
EPSS
2%p83
Published
()
Modified
Description

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.

Vendors
freedesktopcanonicaldebianredhat
Products
poppler, ubuntu linux, debian linux, ansible tower, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-476
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.