CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
89.1%
Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince or Okular.
Security Fix(es):
poppler: heap-based buffer over-read in XRef::getEntry in XRef.cc (CVE-2019-7310)
poppler: heap-based buffer overflow in function ImageStream::getLine() in Stream.cc (CVE-2019-9200)
poppler: infinite recursion in Parser::getObj function in Parser.cc (CVE-2018-16646)
poppler: memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc (CVE-2018-18897)
poppler: reachable abort in Object.h (CVE-2018-19058)
poppler: out-of-bounds read in EmbFile::save2 in FileSpec.cc (CVE-2018-19059)
poppler: pdfdetach utility does not validate save paths (CVE-2018-19060)
poppler: NULL pointer dereference in _poppler_attachment_new (CVE-2018-19149)
poppler: NULL pointer dereference in the XRef::getEntry in XRef.cc (CVE-2018-20481)
poppler: reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc (CVE-2018-20650)
poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc (CVE-2018-20662)
poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc (CVE-2019-9631)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 7 | ppc | poppler-qt | < 0.26.5-38.el7 | poppler-qt-0.26.5-38.el7.ppc.rpm |
RedHat | 7 | ppc64le | poppler-utils | < 0.26.5-38.el7 | poppler-utils-0.26.5-38.el7.ppc64le.rpm |
RedHat | 7 | ppc | poppler-glib | < 0.26.5-38.el7 | poppler-glib-0.26.5-38.el7.ppc.rpm |
RedHat | 7 | i686 | poppler-qt | < 0.26.5-38.el7 | poppler-qt-0.26.5-38.el7.i686.rpm |
RedHat | 7 | s390x | evince-browser-plugin | < 3.28.2-8.el7 | evince-browser-plugin-3.28.2-8.el7.s390x.rpm |
RedHat | 7 | ppc64le | poppler-demos | < 0.26.5-38.el7 | poppler-demos-0.26.5-38.el7.ppc64le.rpm |
RedHat | 7 | ppc64le | evince-browser-plugin | < 3.28.2-8.el7 | evince-browser-plugin-3.28.2-8.el7.ppc64le.rpm |
RedHat | 7 | x86_64 | poppler-utils | < 0.26.5-38.el7 | poppler-utils-0.26.5-38.el7.x86_64.rpm |
RedHat | 7 | ppc64le | poppler-debuginfo | < 0.26.5-38.el7 | poppler-debuginfo-0.26.5-38.el7.ppc64le.rpm |
RedHat | 7 | ppc64 | poppler-devel | < 0.26.5-38.el7 | poppler-devel-0.26.5-38.el7.ppc64.rpm |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
89.1%