Back

MEDIUM

poppler: NULL pointer dereference in Annot.h:AnnotPath::getCoordsLength() allows for denial of service via crafted PDF

Published May 6, 2018

Description

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having low security impact and a future update may address this flaw.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 6, 2018
Updated Aug 5, 2024
Reserved May 6, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 5, 2018