4.3
CVSSv2

CVE-2022-27337

Published: 05/05/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A logic error in the Hints::Hints function of Poppler v22.03.0 allows malicious users to cause a Denial of Service (DoS) via a crafted PDF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler 22.03.0

fedoraproject fedora 36

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1010695 poppler: CVE-2022-27337: Logic error in function Hints::Hints Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 7 May 2022 15:0 ...
Synopsis Moderate: poppler security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for poppler is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as ...
Synopsis Moderate: poppler security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for poppler is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ...
Two vulnerabilities were discovered in poppler, a PDF rendering library, which could result in denial of service or the execution of arbitrary code if a malformed PDF file or JBIG2 image is processed For the stable distribution (bullseye), these problems have been fixed in version 20090-31+deb11u1 We recommend that you upgrade your poppler pac ...
A logic error in the Hints::Hints function of Poppler v22030 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file (CVE-2022-27337) Poppler prior to and including 22080 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStreamcc) Processing a specially crafted PDF file or JBIG2 ima ...
A logic error in the Hints::Hints function of Poppler v22030 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2812 poppler, poppler-glib, poppler-qt5, poppler-qt6 22080-1 22080-2 Unknown Unknown gitlabfreedesktoporg/pop ...