6.5
CVSSv3

CVE-2018-20551

Published: 28/12/2018 Updated: 11/09/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A reachable Object::getString assertion in Poppler 0.72.0 allows malicious users to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler 0.72.0

canonical ubuntu linux 18.10

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

Vendor Advisories

Synopsis Moderate: poppler security update Type/Severity Security Advisory: Moderate Topic An update for poppler is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Several security issues were fixed in poppler ...
Debian Bug report logs - #909802 poppler: CVE-2018-16646 denial-of-service via crafted file Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Markus Koschany <apo@debianorg> Date: Fri, 28 Sep 2018 18:33:02 UTC Severity: ...
Debian Bug report logs - #921215 poppler: CVE-2019-7310: Heap buffer overflow in XRef::getEntry due to integer overflow Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Dat ...
Debian Bug report logs - #918158 poppler: CVE-2018-20662 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 3 Jan 2019 21:57:01 UTC Severity: normal Tags: securi ...
Debian Bug report logs - #917525 poppler: CVE-2018-20551: reachable abort in AnnotRichMedia::Content::Content at Annotcc:6432 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg&gt ...
Debian Bug report logs - #926673 poppler: CVE-2019-9631: heap overflow in downsample_row_box_filter Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 8 Apr 2019 ...
Debian Bug report logs - #917325 poppler: CVE-2018-20481 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 26 Dec 2018 08:36:02 UTC Severity: important Tags: fix ...
Debian Bug report logs - #926532 poppler: CVE-2019-10873 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 6 Apr 2019 15:57:01 UTC Severity: important Tags: fix ...
Debian Bug report logs - #923414 poppler: CVE-2019-9200 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 27 Feb 2019 20:30:02 UTC Severity: important Tags: fixe ...
A reachable Object::getString assertion in Poppler 0720 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annotc ...