Vulnerability Name:

CVE-2013-7296 (CCN-90552)

Assigned:2014-01-16
Published:2014-01-16
Updated:2017-08-29
Summary:The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted PDF file.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MISC
Type: UNKNOWN
http://cgit.freedesktop.org/poppler/poppler/commit/?id=58e04a08afee39370283c494ee2e4e392fd3b684

Source: MITRE
Type: CNA
CVE-2013-7296

Source: FEDORA
Type: UNKNOWN
FEDORA-2014-0156

Source: CCN
Type: Poppler Web site
Poppler

Source: MLIST
Type: UNKNOWN
[oss-security] 20140117 Re: CVE Request - Poppler library: DoS fixed in 0.24.5

Source: CCN
Type: oss-security: Thu, 16 Jan 2014
CVE Request - Poppler library: DoS fixed in 0.24.5

Source: MLIST
Type: UNKNOWN
[oss-security] 20140116 CVE Request - Poppler library: DoS fixed in 0.24.5

Source: SECUNIA
Type: Vendor Advisory
56567

Source: SECUNIA
Type: UNKNOWN
56776

Source: GENTOO
Type: UNKNOWN
GLSA-201401-21

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=1048199

Source: XF
Type: UNKNOWN
poppler-jbig2stream-readsegments-dos(90552)

Source: XF
Type: UNKNOWN
poppler-jbig2stream-readsegments-dos(90552)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:freedesktop:poppler:0.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.5:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.6:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.10.7:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.11.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.11.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.11.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.11.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.12.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.12.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.12.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.12.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.12.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.13.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.13.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.13.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.13.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.13.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.14.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.14.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.14.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.14.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.14.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.14.5:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.15.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.15.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.15.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.15.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.5:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.6:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.16.7:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.17.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.17.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.17.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.17.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.17.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.18.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.18.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.18.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.18.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.18.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.19.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.19.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.19.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.19.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.19.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.20.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.20.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.20.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.20.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.20.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.20.5:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.21.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.21.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.21.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.21.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.21.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.22.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.22.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.22.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.22.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.22.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.23.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.23.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.23.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.23.3:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.23.4:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.24.0:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.24.1:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:0.24.2:*:*:*:*:*:*:*
  • OR cpe:/a:freedesktop:poppler:*:*:*:*:*:*:*:* (Version <= 0.24.3)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20137296
    V
    CVE-2013-7296
    2017-03-01
    oval:com.ubuntu.precise:def:20137296000
    V
    CVE-2013-7296 on Ubuntu 12.04 LTS (precise) - low.
    2014-01-25
    oval:com.ubuntu.xenial:def:201372960000000
    V
    CVE-2013-7296 on Ubuntu 16.04 LTS (xenial) - low.
    2014-01-25
    oval:com.ubuntu.trusty:def:20137296000
    V
    CVE-2013-7296 on Ubuntu 14.04 LTS (trusty) - low.
    2014-01-25
    oval:com.ubuntu.xenial:def:20137296000
    V
    CVE-2013-7296 on Ubuntu 16.04 LTS (xenial) - low.
    2014-01-25
    BACK
    freedesktop poppler 0.1
    freedesktop poppler 0.1.1
    freedesktop poppler 0.1.2
    freedesktop poppler 0.2.0
    freedesktop poppler 0.10.0
    freedesktop poppler 0.10.1
    freedesktop poppler 0.10.2
    freedesktop poppler 0.10.3
    freedesktop poppler 0.10.4
    freedesktop poppler 0.10.5
    freedesktop poppler 0.10.6
    freedesktop poppler 0.10.7
    freedesktop poppler 0.11.0
    freedesktop poppler 0.11.1
    freedesktop poppler 0.11.2
    freedesktop poppler 0.11.3
    freedesktop poppler 0.12.0
    freedesktop poppler 0.12.1
    freedesktop poppler 0.12.2
    freedesktop poppler 0.12.3
    freedesktop poppler 0.12.4
    freedesktop poppler 0.13.0
    freedesktop poppler 0.13.1
    freedesktop poppler 0.13.2
    freedesktop poppler 0.13.3
    freedesktop poppler 0.13.4
    freedesktop poppler 0.14.0
    freedesktop poppler 0.14.1
    freedesktop poppler 0.14.2
    freedesktop poppler 0.14.3
    freedesktop poppler 0.14.4
    freedesktop poppler 0.14.5
    freedesktop poppler 0.15.0
    freedesktop poppler 0.15.1
    freedesktop poppler 0.15.2
    freedesktop poppler 0.15.3
    freedesktop poppler 0.16.0
    freedesktop poppler 0.16.1
    freedesktop poppler 0.16.2
    freedesktop poppler 0.16.3
    freedesktop poppler 0.16.4
    freedesktop poppler 0.16.5
    freedesktop poppler 0.16.6
    freedesktop poppler 0.16.7
    freedesktop poppler 0.17.0
    freedesktop poppler 0.17.1
    freedesktop poppler 0.17.2
    freedesktop poppler 0.17.3
    freedesktop poppler 0.17.4
    freedesktop poppler 0.18.0
    freedesktop poppler 0.18.1
    freedesktop poppler 0.18.2
    freedesktop poppler 0.18.3
    freedesktop poppler 0.18.4
    freedesktop poppler 0.19.0
    freedesktop poppler 0.19.1
    freedesktop poppler 0.19.2
    freedesktop poppler 0.19.3
    freedesktop poppler 0.19.4
    freedesktop poppler 0.20.0
    freedesktop poppler 0.20.1
    freedesktop poppler 0.20.2
    freedesktop poppler 0.20.3
    freedesktop poppler 0.20.4
    freedesktop poppler 0.20.5
    freedesktop poppler 0.21.0
    freedesktop poppler 0.21.1
    freedesktop poppler 0.21.2
    freedesktop poppler 0.21.3
    freedesktop poppler 0.21.4
    freedesktop poppler 0.22.0
    freedesktop poppler 0.22.1
    freedesktop poppler 0.22.2
    freedesktop poppler 0.22.3
    freedesktop poppler 0.22.4
    freedesktop poppler 0.23.0
    freedesktop poppler 0.23.1
    freedesktop poppler 0.23.2
    freedesktop poppler 0.23.3
    freedesktop poppler 0.23.4
    freedesktop poppler 0.24.0
    freedesktop poppler 0.24.1
    freedesktop poppler 0.24.2
    freedesktop poppler *