4.3
CVSSv2

CVE-2019-14494

Published: 01/08/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Poppler up to and including 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 9.0

debian debian linux 10.0

redhat enterprise linux 7.0

redhat enterprise linux 8.0

Vendor Advisories

Debian Bug report logs - #933812 poppler: CVE-2019-14494 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Aug 2019 20:54:02 UTC Severity: normal Tags: securi ...
poppler could be made to crash if it received specially crafted PDF ...
Synopsis Low: evince and poppler security and bug fix update Type/Severity Security Advisory: Low Topic An update for evince and poppler is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (C ...
Synopsis Low: poppler security update Type/Severity Security Advisory: Low Topic An update for poppler is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...
A divide-by-zero error was found in the way Poppler handled certain PDF files A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by an application linked to Poppler, would crash the application causing a denial of service (CVE-2019-14494) ...
A divide-by-zero error was found in the way Poppler handled certain PDF files A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by an application linked to Poppler, would crash the application causing a denial of service (CVE-2019-14494) ...
A divide-by-zero error was found in the way Poppler handled certain PDF files A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by an application linked to Poppler, would crash the application causing a denial of service (CVE-2019-14494) ...