Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-37050
HistoryAug 22, 2023 - 7:16 p.m.

Design/Logic Flaw

2023-08-2219:16:00
PRIOn knowledge base
www.prio-n.com
9
poppler 22.07.0
pdfdoc::savepageas
denial-of-service
xref data structure
getcatalog processing
cve-2018-20662

6.3 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.5%

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

CPENameOperatorVersion
debian_linuxeq10.0
popplereq22.07.0