CVE-2013-1789Poppler vulnerability

8 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
2.8%
top 13.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 9
Latest updateMay 17

Description

splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5wg2-pmq5-5v8v: splash/Splash2022-05-17
CVEList
CVE-2013-1789: splash/Splash2013-04-09

📋Vendor Advisories

3
Ubuntu
poppler vulnerabilities2013-04-02
Red Hat
poppler: Multiple null pointer de-references in the Poppler splash backend2013-01-10
Debian
CVE-2013-1789: poppler - splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to ...2013

💬Community

2
Bugzilla
CVE-2013-1789 poppler: Multiple null pointer de-references in the Poppler splash backend2013-03-01
Bugzilla
CVE-2013-1788 CVE-2013-1789 CVE-2013-1790 poppler various flaws [fedora-all]2013-03-01
CVE-2013-1789 — Freedesktop Poppler vulnerability | cvebase