Severity
9.8CRITICAL
EPSS
2.2%
top 15.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8
Latest updateMay 13

Description

Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Debianpoppler< 0.71.0-4+3

Also affects: Debian Linux 8.0, Fedora 28, 29, 30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3q4x-phpm-jwm5: Poppler 02022-05-13
CVEList
CVE-2019-9631: Poppler 02019-03-08
OSV
CVE-2019-9631: Poppler 02019-03-08

📋Vendor Advisories

3
Ubuntu
poppler vulnerabilities2019-06-27
Red Hat
poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc2019-03-07
Debian
CVE-2019-9631: poppler - Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downs...2019

💬Community

2
Bugzilla
CVE-2019-9631 poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc2019-03-08
Bugzilla
CVE-2019-9631 poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc [fedora-all]2019-03-08
CVE-2019-9631 (CRITICAL CVSS 9.8) | Poppler 0.74.0 has a heap-based buf | cvebase.io