ZeroHour

CVE-2019-7310

PoC
CVSS 3.1
7.8 high
EPSS
2%p81
Published
()
Modified
Description

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.

Vendors
freedesktopcanonicaldebianfedoraprojectredhat
Products
poppler, ubuntu linux, debian linux, fedora, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-125, CWE-681
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.