poppler: multiple invalid memory access flaws
Published Apr 9, 2013
6.8
MEDIUMCVSS 2.0
EPSS 3.87%
Description
poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc.
Affected products
No data.
- ≤ 0.22.0
No data.
Red Hat Enterprise Linux 5
poppler
Will not fix
Red Hat Enterprise Linux 6
poppler
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | poppler | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | poppler | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (18)
- http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=0388837f01bc467045164f9ddaff787000a8caaa x_refsource_CONFIRMExploitPatch
- http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=8b6dc55e530b2f5ede6b9dfb64aafdd1d5836492 x_refsource_CONFIRMExploitPatch
- http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=957aa252912cde85d76c41e9710b33425a82b696 x_refsource_CONFIRMExploitPatch
- http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=bbc2d8918fe234b7ef2c480eb148943922cc0959 x_refsource_CONFIRMExploitPatch
- http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=e14b6e9c13d35c9bd1e0c50906ace8e707816888 x_refsource_CONFIRMExploitPatch
- http://j00ru.vexillium.org/?p=1507 x_refsource_MISC
- http://lists.fedoraproject.org/pipermail/package-announce/2013-March/100081.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-March/100090.html vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/52846 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://ubuntu.com/usn/usn-1785-1 vendor-advisoryx_refsource_UBUNTU
- http://www.debian.org/security/2013/dsa-2719 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:143 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2013/02/28/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2013/02/28/8 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2013-1788 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=917108 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-1788
- https://www.cve.org/CVERecord?id=CVE-2013-1788
Change history (0)
No recorded changes yet.