VDB

GCVE-VVD-MAGEIA-2019-117

GCVE-VVD-MAGEIA-2019-117
Advisory Published
Vulnetix · Advisory published September 6, 2019
The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing. (CVE-2018-20662) A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. (CVE-2019-9200)

Affected Products

VendorProductVersionsPlatforms
Mageiaiptables0 (affected), 1.8.2-5.1.mga7 (unaffected)
Mageiapoppler0 (affected), 0.52.0-3.12.mga6 (unaffected), 0 (affected), 0.52.0-3.12.mga6 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›