Back

HIGH

poppler: heap-based buffer overflow via a crafted PDF document

Published Dec 25, 2020

Description

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects

Affected products

Remediation

Red Hat statement

The versions of `poppler` as shipped with Red Hat Enterprise Linux are not affected by this flaw, as the vulnerable code was introduced in a newer version of the package.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 25, 2020
Updated Aug 4, 2024
Reserved Dec 25, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 20, 2020
ENISA EUVD
Assigner mitre
Published Dec 25, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-23360