CVE-2020-36024

Severity
5.5MEDIUM
EPSS
0.1%
top 73.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 11
Latest updateAug 17

Description

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDfreedesktop/poppler20.12.1
Debianpoppler< 20.09.0-3.1+deb11u2+3
Ubuntupoppler< 0.86.1-0ubuntu1.3+2

Patches

🔴Vulnerability Details

4
OSV
poppler vulnerabilities2023-08-17
GHSA
GHSA-4pj9-rq3x-vjw5: An issue was discovered in freedesktop poppler version 202023-08-11
OSV
CVE-2020-36024: An issue was discovered in freedesktop poppler version 202023-08-11
CVEList
CVE-2020-36024: An issue was discovered in freedesktop poppler version 202023-08-11

📋Vendor Advisories

3
Ubuntu
poppler vulnerabilities2023-08-17
Red Hat
poppler: NULL pointer dereference in `FoFiType1C::convertToType1`2023-08-11
Debian
CVE-2020-36024: poppler - An issue was discovered in freedesktop poppler version 20.12.1, allows remote at...2020
CVE-2020-36024 (MEDIUM CVSS 5.5) | An issue was discovered in freedesk | cvebase.io