poppler: Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Published Jul 31, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.90%
Description
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Affected products
No data.
- < 23.06.0
No data.
Red Hat Enterprise Linux 6
poppler
Not affected
Red Hat Enterprise Linux 7
compat-poppler022
Not affected
Red Hat Enterprise Linux 7
poppler
Not affected
Red Hat Enterprise Linux 8
gimp:flatpak/poppler
Not affected
Red Hat Enterprise Linux 8
inkscape:flatpak/poppler
Not affected
Red Hat Enterprise Linux 8
libreoffice:flatpak/poppler
Not affected
Red Hat Enterprise Linux 8
poppler
Not affected
Red Hat Enterprise Linux 9
inkscape:flatpak/poppler
Not affected
Red Hat Enterprise Linux 9
libreoffice:flatpak/poppler
Not affected
Red Hat Enterprise Linux 9
poppler
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | poppler | Not affected | n/a |
| Red Hat Enterprise Linux 7 | compat-poppler022 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | poppler | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gimp:flatpak/poppler | Not affected | n/a |
| Red Hat Enterprise Linux 8 | inkscape:flatpak/poppler | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libreoffice:flatpak/poppler | Not affected | n/a |
| Red Hat Enterprise Linux 8 | poppler | Not affected | n/a |
| Red Hat Enterprise Linux 9 | inkscape:flatpak/poppler | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libreoffice:flatpak/poppler | Not affected | n/a |
| Red Hat Enterprise Linux 9 | poppler | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 6, 7, 8, and 9 are not affected by this CVE, as the vulnerable code is not present in RHEL.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (13)
- https://access.redhat.com/security/cve/CVE-2023-34872 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2227884 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-38912 Advisory
- https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe Patch
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399 ExploitIssue TrackingVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3XXL3L6RJOTLGCN7GLH2OLLNF4FJ4T7I/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ3NYJ43U2MA7COKGMJDARZUAAOP45D4/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SFBT75QHBWNMSDAHSXZQ2I3PBJWID36K/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W3H3GOWFE3C7543GMEN7LY4GWMWJ7D2G/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3XXL3L6RJOTLGCN7GLH2OLLNF4FJ4T7I/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ3NYJ43U2MA7COKGMJDARZUAAOP45D4/
- https://nvd.nist.gov/vuln/detail/CVE-2023-34872
- https://www.cve.org/CVERecord?id=CVE-2023-34872
Change history (0)
No recorded changes yet.