SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-13988

Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite.

MEDIUM 6.5EPSS 3.15%

Does this matter?

Lower severity and a low EPSS score (3.15%). Track it; it rarely justifies an emergency change on its own.

Description

Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
3.15% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
freedesktop/poppler · canonical/ubuntu linux · debian/debian linux · redhat/ansible tower · redhat/openshift container platform · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.