Back

HIGH

poppler: recursive function call in JBIG2Stream::readTextRegion() in JBIG2Stream.cc causing denial of service

Published Mar 1, 2019

Description

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.

Affected products

Remediation

Red Hat statement

This flaw was found to be a duplicate of $DUP. Please see https://access.redhat.com/security/cve/$DUP for information about affected products and security errata.

Metrics

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 1, 2019
Updated Aug 4, 2024
Reserved Mar 1, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Feb 28, 2019