Asymmetric denial of service In poppler
Description
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 0.85.0-2 | ||
debian 14 | 0.85.0-2 | ||
debian 11 | 0.85.0-2 | ||
rpm rhel7 | 0:4.10.5-7.el7 | ||
debian 12 | 0.85.0-2 | ||
rpm rhel7 | 0:3.28.2-8.el7 | ||
rpm rhel5 | - | - | |
rpm rhel7 | 0:0.26.5-38.el7 | ||
rpm rhel6 | - | - | |
rpm rhel8 | 0:0.66.0-11.el8_0.12 |
Aliases
1. 2. 3. 4. 5.