Bug 2231510 (CVE-2020-36023) - CVE-2020-36023 poppler: Stack-Overflow in `FoFiType1C::cvtGlyph`
Summary: CVE-2020-36023 poppler: Stack-Overflow in `FoFiType1C::cvtGlyph`
Keywords:
Status: NEW
Alias: CVE-2020-36023
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2231511 2231512 2231513 2231514 2231515 2231516 2231517 2231518 2231519
Blocks: 2231528
TreeView+ depends on / blocked
 
Reported: 2023-08-11 18:26 UTC by Pedro Sampaio
Modified: 2023-09-27 12:28 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2023-08-11 18:26:40 UTC
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

References:

https://gitlab.freedesktop.org/poppler/poppler/-/issues/1013

Comment 1 Pedro Sampaio 2023-08-11 18:27:28 UTC
Created mingw-poppler tracking bugs for this issue:

Affects: fedora-all [bug 2231519]


Created poppler tracking bugs for this issue:

Affects: fedora-all [bug 2231518]


Note You need to log in before you can comment on or make changes to this bug.