CVE-2018-13988
Summary
| CVE | CVE-2018-13988 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-25 23:29:00 UTC |
| Updated | 2019-04-25 14:16:00 UTC |
| Description | Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| USN-3757-1: poppler vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Bug 1102531 – VUL-1: poppler: CVE-2018-13988 poppler: buffer overflow in pdfunite |
CONFIRM |
bugzilla.novell.com |
Issue Tracking, Third Party Advisory |
| 1602838 – (CVE-2018-13988) CVE-2018-13988 poppler: out of bounds read in pdfunite |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| PDFunite 0.62.0 Buffer Overflow ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| poppler/poppler - The poppler pdf rendering library (mirrored from https://gitlab.freedesktop.org/poppler/poppler) |
CONFIRM |
cgit.freedesktop.org |
Patch, Vendor Advisory |
| [SECURITY] [DLA 1562-1] poppler security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296090 Oracle Solaris 11.4 Support Repository Update (SRU) 5.1.3 Missing (CPUJAN2019)
- 751420 SUSE Enterprise Linux Security Update for poppler (SUSE-SU-2021:3854-1)
- 751427 OpenSUSE Security Update for poppler (openSUSE-SU-2021:3854-1)
- 754197 SUSE Enterprise Linux Security Update for poppler (SUSE-SU-2023:2907-1)
- 754198 SUSE Enterprise Linux Security Update for poppler (SUSE-SU-2023:2906-1)