CVE-2018-20481
poppler: NULL pointer dereference in the XRef::getEntry in XRef.cc
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
XRef::getEntry en XRef.cc en Poppler 0.72.0 gestiona de manera incorrecta las entradas XRef no asignadas, lo que permite que los atacantes remotos provoquen una denegación de servicio (desreferencia de puntero NULL) mediante un documento PDF manipulado, cuando se llama a XRefEntry::setFlag, en XRef.h, desde Parser::makeStream en Parser.cc.
Poppler is a Portable Document Format rendering library, used by applications such as Evince or Okular. Issues addressed include buffer overflow and null pointer vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-25 CVE Reserved
- 2018-12-26 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106321 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2019/03/msg00008.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2020/07/msg00018.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://gitlab.freedesktop.org/poppler/poppler/issues/692 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://gitlab.freedesktop.org/poppler/poppler/merge_requests/143 | 2020-07-23 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:2022 | 2020-07-23 | |
https://access.redhat.com/errata/RHSA-2019:2713 | 2020-07-23 | |
https://usn.ubuntu.com/3865-1 | 2020-07-23 | |
https://access.redhat.com/security/cve/CVE-2018-20481 | 2019-09-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1665266 | 2019-09-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freedesktop Search vendor "Freedesktop" | Poppler Search vendor "Freedesktop" for product "Poppler" | 0.72.0 Search vendor "Freedesktop" for product "Poppler" and version "0.72.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.10" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|