8.8
CVSSv3

CVE-2018-21009

Published: 05/09/2019 Updated: 23/07/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Poppler prior to 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler

Vendor Advisories

Synopsis Moderate: poppler and evince security update Type/Severity Security Advisory: Moderate Topic An update for poppler and evince is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
An issue was discovered in Poppler 0740 There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDevcc (CVE-2019-10871) Poppler before 0660 has an integer overflow in Parser::makeStream in Parsercc(CVE-2018-21009) The JPXStream::init function in Poppler 0780 and earlier doesn't check for negative valu ...
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3320 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files (CVE-2019-11459) Poppler before 0660 has an integer overflow in Parser::makeStream ...
Impact: Low Public Date: 2019-09-05 CWE: CWE-190 Bugzilla: 1753850: CVE-2018-21009 poppler: integer ove ...