Heap-Based Buffer Over-Read in Poppler Software by FreeDesktop
CVE-2019-10872

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
5 April 2019

What is CVE-2019-10872?

A vulnerability has been identified in Poppler 0.74.0 which can lead to a heap-based buffer over-read in the function Splash::blitTransparent. This flaw may allow attackers to exploit the vulnerability, potentially leading to information disclosure. It's essential for users of this version to apply the necessary security updates to prevent possible exploits. References for remediation include security advisories from various distribution platforms.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.