6.8
CVSSv2

CVE-2019-12293

Published: 23/05/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Poppler up to and including 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler

Vendor Advisories

Several security issues were fixed in poppler ...
Synopsis Moderate: poppler security update Type/Severity Security Advisory: Moderate Topic An update for poppler is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Moderate: poppler and evince security update Type/Severity Security Advisory: Moderate Topic An update for poppler and evince is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Debian Bug report logs - #926530 poppler: CVE-2019-10872 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 6 Apr 2019 15:51:02 UTC Severity: important Tags: fix ...
Debian Bug report logs - #929423 poppler: CVE-2019-12293 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 23 May 2019 08:54:02 UTC Severity: important Tags: fix ...
An issue was discovered in Poppler 0740 There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDevcc (CVE-2019-10871) Poppler before 0660 has an integer overflow in Parser::makeStream in Parsercc(CVE-2018-21009) The JPXStream::init function in Poppler 0780 and earlier doesn't check for negative valu ...
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3320 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files (CVE-2019-11459) Poppler before 0660 has an integer overflow in Parser::makeStream ...
Impact: Moderate Public Date: 2019-05-23 CWE: CWE-122 Bugzilla: 1713582: CVE-2019-12293 poppler: heap-b ...