Out-of-bounds read In poppler
Description
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:0.5.4-4.4.el5_4.11 | ||
rpm rhel5 | 0:3.0-33.8.el5_5.5 | ||
rpm rhel5 | 1:1.3.7-11.el5_4.3 | ||
debian 11 | 3.02-2 | ||
debian 11 | 0.12.2-1 | ||
debian 12 | 3.02-2 | ||
debian 12 | 0.12.2-1 | ||
debian 13 | 3.02-2 | ||
debian 13 | 0.12.2-1 | ||
debian 14 | 3.02-2 |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5.