cbcvebase.
CVE-2019-7310
published 2019-02-03

CVE-2019-7310: In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to…

PriorityP434high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.20%
80.5th percentile
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianpoppler< poppler 0.71.0-4 (bookworm)poppler 0.71.0-4 (bookworm)
fedoraprojectfedora
freedesktoppoppler
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.71.0-40.71.0-4
freedesktoppoppler>= 0 < 0.24.5-2ubuntu4.160.24.5-2ubuntu4.16
freedesktoppoppler>= 0 < 0.41.0-0ubuntu1.120.41.0-0ubuntu1.12
freedesktoppoppler>= 0 < 0.62.0-2ubuntu2.70.62.0-2ubuntu2.7
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.