Skip to content

Commit

Permalink
poppler: CVE-2024-6239
Browse files Browse the repository at this point in the history
A flaw was found in the Poppler's Pdfinfo utility. This issue
occurs when using -dests parameter with pdfinfo utility. By
using certain malformed input files, an attacker could cause
the utility to crash, leading to a denial of service.

CVE-2024-6239-0002 is the CVE fix and CVE-2024-6239-0001 is
dependent commit to fix the CVE.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2024-6239

Upstream patch:
https://gitlab.freedesktop.org/poppler/poppler/-/commit/0554731052d1a97745cb179ab0d45620589dd9c4
https://gitlab.freedesktop.org/poppler/poppler/-/commit/fc1c711cb5f769546c6b31cc688bf0ee7f0c1dbc

Signed-off-by: Yogita Urade <[email protected]>
Signed-off-by: Armin Kuster <[email protected]>
  • Loading branch information
yogi-u authored and akuster committed Aug 21, 2024
1 parent b7148eb commit c432a61
Show file tree
Hide file tree
Showing 3 changed files with 1,388 additions and 0 deletions.
Loading

0 comments on commit c432a61

Please sign in to comment.