Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
BID:59363
Info
Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 59363 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-1789 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2013 12:00AM |
| Updated: | May 07 2015 05:05PM |
| Credit: | Marcus Meissner |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 S.u.S.E. openSUSE 11.4 Poppler poppler 0.22.1 Oracle Solaris 11.1 Oracle Solaris 10 Gentoo Linux |
| Not Vulnerable: |
Oracle Solaris 11.1.10.5.0 |
Discussion
Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
Poppler is prone to multiple denial-of-service when handling malformed PDF files.
Successfully exploiting these issues allows remote attackers to crash applications that use the vulnerable library, denying service to legitimate users.
Note: These issues were previously discussed in BID 58198 (Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities), but have been moved to their own record to better document them.
Poppler 0.22.1 is vulnerable; other versions may also be affected.
Poppler is prone to multiple denial-of-service when handling malformed PDF files.
Successfully exploiting these issues allows remote attackers to crash applications that use the vulnerable library, denying service to legitimate users.
Note: These issues were previously discussed in BID 58198 (Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities), but have been moved to their own record to better document them.
Poppler 0.22.1 is vulnerable; other versions may also be affected.
Exploit / POC
Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
To exploit these issues an attacker must entice an unsuspecting user to open a malicious PDF file.
The vendor has received an example PDF file from the reporter that demonstrates these issues. This file is not known to be publicly available.
To exploit these issues an attacker must entice an unsuspecting user to open a malicious PDF file.
The vendor has received an example PDF file from the reporter that demonstrates these issues. This file is not known to be publicly available.
Solution / Fix
Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
References:
References:
- CVE Request: poppler 0.22.1 security fixes (Marcus Meissner)
- Poppler Homepage (Poppler)