6.5
CVE-2018-13988
- EPSS 3.15%
- Veröffentlicht 25.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:22
- Erkennungen
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freedesktop ≫ Poppler Version <= 0.62.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Ansible Tower Version 3.3.0
Redhat ≫ Openshift Container Platform Version 3.11
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.15% | 0.863 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://access.redhat.com/errata/RHSA-2018:3505
https://access.redhat.com/errata/RHBA-2019:0327
https://access.redhat.com/errata/RHSA-2018:3140
https://lists.debian.org/debian-lts-announce/2018/10/msg00024.html
http://packetstormsecurity.com/files/148661/PDFunite-0.62.0-Buffer-Overflow.html
https://bugzilla.novell.com/show_bug.cgi?id=CVE-2018-13988
https://bugzilla.redhat.com/show_bug.cgi?id=1602838
https://cgit.freedesktop.org/poppler/poppler/commit/?id=004e3c10df0abda214f0c293f9e269fdd979c5ee
https://usn.ubuntu.com/3757-1/