NULL Pointer Dereference in Poppler Affected by Version 0.74.0
CVE-2019-10873

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 April 2019

What is CVE-2019-10873?

A vulnerability present in Poppler 0.74.0 allows for a NULL pointer dereference in the function SplashClip::clipAALine, which could potentially lead to application crashes. This flaw can be exploited if the affected software processes specially crafted input, making it critical for users to stay updated with patches and security measures to mitigate risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.