Division by zero in Poppler - CVE-2019-14494

 

Division by zero in Poppler - CVE-2019-14494

Published: August 12, 2019


Vulnerability identifier: #VU20053
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14494
CWE-ID: CWE-369
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to division by zero error when processing untrusted input in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. A remote attacker can create a specially crafted PDF file and crash the application.


Affected software

Poppler
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for x86_64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Workstation Extension
Fedora
poppler (Red Hat package)
poppler (Ubuntu package)
evince (Red Hat package)
libpoppler-cpp0-debuginfo
typelib-1_0-Poppler-0_18
poppler-tools-debuginfo
poppler-tools
libpoppler-glib8-debuginfo
libpoppler-glib8
libpoppler-glib-devel
libpoppler-devel
libpoppler-cpp0
poppler-debugsource
libpoppler73-debuginfo
libpoppler73
poppler

How to mitigate CVE-2019-14494

Install update from vendor's website.

Poppler - update to 0.79.0
poppler (Red Hat package) - addressed in versions 0.26.5-43.el7, 0.66.0-27.el8
poppler (Ubuntu package) - addressed in versions 0.62.0-2ubuntu2.10, 0.74.0-0ubuntu1.3
evince (Red Hat package) - update to 3.28.2-10.el7
libpoppler-cpp0-debuginfo - update to 0.62.0-4.6.1
typelib-1_0-Poppler-0_18 - update to 0.62.0-4.6.1
poppler-tools-debuginfo - update to 0.62.0-4.6.1
poppler-tools - update to 0.62.0-4.6.1
libpoppler-glib8-debuginfo - update to 0.62.0-4.6.1
libpoppler-glib8 - update to 0.62.0-4.6.1
libpoppler-glib-devel - update to 0.62.0-4.6.1
libpoppler-devel - update to 0.62.0-4.6.1
libpoppler-cpp0 - update to 0.62.0-4.6.1
poppler-debugsource - update to 0.62.0-4.6.1
libpoppler73-debuginfo - update to 0.62.0-4.6.1
libpoppler73 - update to 0.62.0-4.6.1
poppler - addressed in versions 0.73.0-16.fc30, 0.73.0-16.fc31

External References

Related Security Bulletins