Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-37050
HistoryAug 22, 2023 - 12:00 a.m.

CVE-2022-37050

2023-08-2200:00:00
ubuntu.com
ubuntu.com
10
poppler 22.07.0
pdfdoc::savepageas
denial-of-service
sigabrt
crafting pdf file
xref data structure
getcatalog processing
incomplete patch

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.012 Low

EPSS

Percentile

85.5%

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to
cause a denial-of-service (application crashes with SIGABRT) by crafting a
PDF file in which the xref data structure is mishandled in getCatalog
processing. Note that this vulnerability is caused by the incomplete patch
of CVE-2018-20662.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpoppler< 0.62.0-2ubuntu2.14+esm2UNKNOWN
ubuntu20.04noarchpoppler< 0.86.1-0ubuntu1.4UNKNOWN
ubuntu22.04noarchpoppler< 22.02.0-2ubuntu0.3UNKNOWN
ubuntu16.04noarchpoppler< 0.41.0-0ubuntu1.16+esm4UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.012 Low

EPSS

Percentile

85.5%