CVE-2019-9545

Source
https://cve.org/CVERecord?id=CVE-2019-9545
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9545.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-9545
Downstream
Related
Published
2019-03-01T19:29:02.930Z
Modified
2026-07-08T19:51:50.568853Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.

References

Affected packages

Git / gitlab.freedesktop.org/poppler/poppler

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/poppler/poppler
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:freedesktop:poppler:0.74.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.74.0"
        },
        {
            "last_affected": "0.74.0"
        }
    ]
}

Affected versions

0.*
0.74.0
poppler-0.*
poppler-0.74.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9545.json"