cbcvebase.
CVE-2019-7310
published 2019-02-03

CVE-2019-7310: In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianpoppler< poppler 0.71.0-4 (bookworm)poppler 0.71.0-4 (bookworm)
fedoraprojectfedora
freedesktoppoppler
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.24.5-2ubuntu4.160.24.5-2ubuntu4.16
freedesktoppoppler>= 0 < 0.41.0-0ubuntu1.120.41.0-0ubuntu1.12
freedesktoppoppler>= 0 < 0.62.0-2ubuntu2.70.62.0-2ubuntu2.7
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH