#VU16349 Improper input validation in Poppler - CVE-2018-19058
Published: December 10, 2018
Poppler
Freedesktop.org
Description
The vulnerability allows a remote attacker to cause DoS condicion on the target system.
The vulnerability exists in the EmbFile::save2 function due to insufficient stream checks by the EmbFile::save2 function, as defined in the FileSpec.cc source code file of the affected software, before an embedded file is saved. A remote attacker can trick the victim into accessing an embedded file that submits malicious input, trigger a reachable abort condition in the Object.h file and cause the service to crash.