CVE-2024-6239

Source
https://cve.org/CVERecord?id=CVE-2024-6239
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6239.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6239
Downstream
ALPINE (1)
BELL (1)
CLSA (1)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
OESA (2)
openSUSE (1)
RHSA (2)
RLSA (1)
ROOT (1)
SUSE (3)
UBUNTU (1)
Related
Published
2024-06-21T13:28:23Z
Modified
2026-08-12T03:51:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Poppler: pdfinfo: crash in broken documents when using -dests parameter
Details

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-20"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6239.json"
}
References

Affected packages

Git / gitlab.freedesktop.org/poppler/poppler

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/poppler/poppler
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "24.06.0"
        },
        {
            "last_affected":  "24.06.1"
        },
        {
            "introduced":  "0"
        },
        {
            "fixed":  "24.06.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6239.json"