PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
References
| Link | Resource |
|---|---|
| https://research.loginsoft.com/bugs/stack-based-buffer-overflows-in-dictfind-poppler-0-74-0/ | Exploit Third Party Advisory |
| https://gitlab.freedesktop.org/poppler/poppler/issues/741 | Exploit Third Party Advisory |
| http://www.securityfocus.com/bid/107560 | Third Party Advisory VDB Entry |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ6RABASMSIMMWMDZTP6ZWUWZPTBSVB5/ | Mailing List Release Notes Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWWVIYFXM74KJFIDHP4W67HR4FRF2LDE/ | Mailing List Release Notes Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XGYLZZ4DZUDBQEGCNDWSZPSFNNZJF4S6/ | |
| https://usn.ubuntu.com/4042-1/ | |
| https://access.redhat.com/errata/RHSA-2019:2713 |
Information
Published : 2019-03-21 18:29
Updated : 2020-08-24 17:37
NVD link : CVE-2019-9903
Mitre link : CVE-2019-9903
JSON object : View
Products Affected
fedoraproject
- fedora
freedesktop
- poppler
CWE
CWE-787
Out-of-bounds Write
