Bug 2227884 (CVE-2023-34872) - CVE-2023-34872 poppler: Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Summary: CVE-2023-34872 poppler: Denial of Service (DoS) (crash) via a crafted PDF fil...
Keywords:
Status: NEW
Alias: CVE-2023-34872
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2227886 2227889 2227890 2227891 2227892 2227893 2227894 2250822 2250823
Blocks: 2227883
TreeView+ depends on / blocked
 
Reported: 2023-07-31 18:45 UTC by Patrick Del Bello
Modified: 2023-11-21 16:23 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2023-07-31 18:45:15 UTC
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe
https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399

Comment 2 Sandipan Roy 2023-11-21 10:06:55 UTC
Created mingw-poppler tracking bugs for this issue:

Affects: fedora-all [bug 2250822]


Created poppler tracking bugs for this issue:

Affects: fedora-all [bug 2250823]


Note You need to log in before you can comment on or make changes to this bug.