CVE-2022-37050

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freedesktop:poppler:22.07.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:14

Type Values Removed Values Added
Summary
  • (es) En Poppler 22.07.0, PDFDoc::savePageAs en PDFDoc.c permite a los atacantes provocar una denegación de servicio (la aplicación se bloquea con SIGABRT) mediante la creación de un archivo PDF en el que la estructura de datos xref se maneja incorrectamente en el procesamiento getCatalog. Tenga en cuenta que esta vulnerabilidad está causada por el parche incompleto de CVE-2018-20662.
References () https://gitlab.freedesktop.org/poppler/poppler/-/commit/dcd5bd8238ea448addd102ff045badd0aca1b990 - Patch () https://gitlab.freedesktop.org/poppler/poppler/-/commit/dcd5bd8238ea448addd102ff045badd0aca1b990 - Patch
References () https://gitlab.freedesktop.org/poppler/poppler/-/issues/1274 - Exploit, Issue Tracking () https://gitlab.freedesktop.org/poppler/poppler/-/issues/1274 - Exploit, Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2023/10/msg00022.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2023/10/msg00022.html - Mailing List, Third Party Advisory

08 Dec 2023, 20:57

Type Values Removed Values Added
First Time Debian debian Linux
Debian
References (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00022.html - (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00022.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Information

Published : 2023-08-22 19:16

Updated : 2024-11-21 07:14


NVD link : CVE-2022-37050

Mitre link : CVE-2022-37050

CVE.ORG link : CVE-2022-37050


JSON object : View

Products Affected

debian

  • debian_linux

freedesktop

  • poppler