PT-2023-5944 · Poppler+4 · Poppler+4

CVE-2020-23804

·

Publicado

2023-08-11

·

Atualizado

2023-12-08

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Poppler version 0.89.0
Description The issue is related to uncontrolled recursion in the Poppler library for rendering PDF files. This can be exploited by a remote attacker to cause a denial of service via crafted input. The vulnerability affects the pdfinfo and pdftops components.
Recommendations For Poppler version 0.89.0, consider disabling the pdfinfo and pdftops functions until a patch is available to prevent potential denial of service attacks.

Exploit

Correção

DoS

NULL Pointer Dereference

Uncontrolled Recursion

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06640
BDU:2023-06641
CVE-2020-23804
DLA-3620-1
OESA-2023-1561
OESA-2023-1611
OESA-2023-1612
OESA-2023-1613
OPENSUSE-SU-2023_3983-1
OPENSUSE-SU-2023_3998-1
SUSE-SU-2023:3981-1
SUSE-SU-2023:3982-1
SUSE-SU-2023:3983-1
SUSE-SU-2023:3998-1
SUSE-SU-2023_3981-1
SUSE-SU-2023_3982-1
SUSE-SU-2023_3983-1
SUSE-SU-2023_3998-1
USN-6508-1
USN-6508-2

Produtos afetados

Astra Linux
Linuxmint
Poppler
Suse
Ubuntu