Denial of Service Vulnerability in Poppler Software
CVE-2009-0755

Currently unrated

Key Information:

Vendor

Poppler

Status
Vendor
CVE Published:
3 March 2009

What is CVE-2009-0755?

The FormWidgetChoice::loadDefaults function in Poppler before version 0.10.4 contains a vulnerability that enables remote attackers to trigger a denial of service (DoS) condition. This is achieved by sending specially crafted PDF files containing an invalid Form Opt entry, which leads to application crashes. Users of Poppler should ensure they are running an updated version to mitigate this risk.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.