Vulnerability Name: | CVE-2019-9545 (CCN-157792) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2019-02-28 | ||||||||||||||||||||||||||||||||||||
Published: | 2019-02-28 | ||||||||||||||||||||||||||||||||||||
Updated: | 2021-07-21 | ||||||||||||||||||||||||||||||||||||
Summary: | An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-9545 Source: XF Type: UNKNOWN poppler-cve20199545-dos(157792) Source: MISC Type: Exploit, Third Party Advisory https://gitlab.freedesktop.org/poppler/poppler/issues/731 Source: CCN Type: Poppler Web site Poppler Source: MISC Type: Exploit, Third Party Advisory https://research.loginsoft.com/bugs/recursive-function-call-in-function-jbig2streamreadtextregion-poppler-0-74-0/ Source: CCN Type: Loginsoft Web site Recursive function call in function JBIG2Stream::readGenericBitmap() poppler 0.74.0 Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-9545 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |