CVE-2019-9903 PUBLISHED

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.

EPSS 0.73% · 72.6th percentile

Risk Scores

EPSS Score
0.73%
72.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpoppler0, 0.33.0-0ubuntu3, 0.37.0-0ubuntu1
Ubuntu:18.04:LTSpoppler0, 0.57.0-2ubuntu4, 0.57.0-2ubuntu5

Timeline

References

Open in Interactive Console →