ZeroHour

CVE-2019-9903

PoC ×2
CVSS 3.1
6.5 medium
EPSS
2%p83
Published
()
Modified
Description

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.

Vendors
freedesktopfedoraprojectdebiancanonicalredhat
Products
poppler, fedora, debian linux, ubuntu linux, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.