CVE-2020-27778

CWE-8247 documents7 sources
Severity
7.5HIGH
EPSS
0.3%
top 48.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3
Latest updateMay 24

Description

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDfreedesktop/poppler< 0.76.0
Debianpoppler< 0.85.0-2+3
CVEListV5popplerpoppler 0.76.0

Also affects: Debian Linux 10.0, Enterprise Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9f25-w4h3-5q5x: A flaw was found in Poppler in the way certain PDF files were converted into HTML2022-05-24
OSV
CVE-2020-27778: A flaw was found in Poppler in the way certain PDF files were converted into HTML2020-12-03
CVEList
CVE-2020-27778: A flaw was found in Poppler in the way certain PDF files were converted into HTML2020-12-03

📋Vendor Advisories

3
Ubuntu
poppler vulnerabilities2020-11-25
Debian
CVE-2020-27778: poppler - A flaw was found in Poppler in the way certain PDF files were converted into HTM...2020
Red Hat
poppler: pdftohtml: access to uninitialized pointer could lead to DoS2019-03-22
CVE-2020-27778 (HIGH CVSS 7.5) | A flaw was found in Poppler in the | cvebase.io