Divide-by-Zero Vulnerability in Poppler PDF Rendering Library
CVE-2019-14494

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
1 August 2019

What is CVE-2019-14494?

A divide-by-zero error exists in the SplashOutputDev::tilingPatternFill function of the Poppler PDF rendering library, impacting versions up to 0.78.0. This vulnerability may lead to unexpected behavior or crashes when handling certain PDF files. It is crucial for users of Poppler to stay updated on security patches and verify that they are running a secure version of the library to avoid exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.