PT-2023-5944 · Poppler+4 · Poppler+4
CVE-2020-23804
·
Publicado
2023-08-11
·
Atualizado
2023-12-08
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Poppler version 0.89.0
Description
The issue is related to uncontrolled recursion in the Poppler library for rendering PDF files. This can be exploited by a remote attacker to cause a denial of service via crafted input. The vulnerability affects the
pdfinfo and pdftops components.Recommendations
For Poppler version 0.89.0, consider disabling the
pdfinfo and pdftops functions until a patch is available to prevent potential denial of service attacks.Exploit
Correção
DoS
NULL Pointer Dereference
Uncontrolled Recursion
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Astra Linux
Linuxmint
Poppler
Suse
Ubuntu