Lucene search

K
redosRedosROS-20230918-04
HistorySep 18, 2023 - 12:00 a.m.

ROS-20230918-04

2023-09-1800:00:00
redos.red-soft.ru
12
poppler pdf
vulnerability
denial of service
thread checking
pdf file
data structure
xref
reachable statement
object::getstring
pdfdoc::replacepagedict
remote attacker

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.0005 Low

EPSS

Percentile

17.8%

A vulnerability in the Poppler PDF rendering library is related to the lack of thread checking before
saving the embedded main function file in pdfunite.cc. Exploitation of the vulnerability could allow
an attacker acting remotely to cause a denial of service.

A vulnerability in the Poppler PDF rendering library is associated with a PDF file in which the data structure
xref is not properly handled when processing getCatalog. Exploitation of the vulnerability could allow
an attacker acting remotely to cause a denial of service.

A vulnerability in the Poppler PDF rendering library is related to the reachable statement
Object::getString. Exploitation of the vulnerability could allow an attacker acting remotely to cause a
a denial of service due to a failure in markObject.

A vulnerability in the Poppler PDF rendering library is related to the lack of thread validation prior to
saving an embedded file in PDFDoc::replacePageDict in PDFDoc.cc. Exploitation of the vulnerability could
Allow an attacker acting remotely to cause a denial of service

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64poppler<= 21.08.0-14UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.0005 Low

EPSS

Percentile

17.8%