Bug 2234528 (CVE-2022-37051) - CVE-2022-37051 poppler: abort in main() in pdfunite.cc
Summary: CVE-2022-37051 poppler: abort in main() in pdfunite.cc
Keywords:
Status: NEW
Alias: CVE-2022-37051
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2234549 2234550 2234551 2234552 2234553 2234555 2234556 2234557 2234559 2234560 2234562 2234563 2234564 2234565 2234566
Blocks: 2234525
TreeView+ depends on / blocked
 
Reported: 2023-08-24 18:43 UTC by Guilherme de Almeida Suckevicz
Modified: 2024-10-23 18:27 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2024:8405 0 None None None 2024-10-23 18:27:36 UTC

Description Guilherme de Almeida Suckevicz 2023-08-24 18:43:13 UTC
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.

Reference:
https://gitlab.freedesktop.org/poppler/poppler/-/issues/1276
https://gitlab.freedesktop.org/poppler/poppler/-/commit/4631115647c1e4f0482ffe0491c2f38d2231337b

Comment 1 Guilherme de Almeida Suckevicz 2023-08-24 18:57:55 UTC
Created mingw-poppler tracking bugs for this issue:

Affects: fedora-all [bug 2234549]


Created poppler tracking bugs for this issue:

Affects: fedora-all [bug 2234550]


Note You need to log in before you can comment on or make changes to this bug.