VulnerabilityModified
CVE-2018-13988
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite.
MEDIUM 6.5EPSS 3.15%
Does this matter?
Lower severity and a low EPSS score (3.15%). Track it; it rarely justifies an emergency change on its own.
Description
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 3.15% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- freedesktop/poppler · canonical/ubuntu linux · debian/debian linux · redhat/ansible tower · redhat/openshift container platform · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/148661/PDFunite-0.62.0-Buffer-Overflow.htmlThird Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=CVE-2018-13988Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1602838Issue Tracking, Third Party Advisory
- https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5eePatch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00024.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3757-1/Third Party Advisory
- http://packetstormsecurity.com/files/148661/PDFunite-0.62.0-Buffer-Overflow.htmlThird Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=CVE-2018-13988Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1602838Issue Tracking, Third Party Advisory
- https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5eePatch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00024.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3757-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.