Integer overflow in Poppler - CVE-2018-21009

 

Integer overflow in Poppler - CVE-2018-21009

Published: September 5, 2019


Vulnerability identifier: #VU20888
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-21009
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in Parser::makeStream() function in Parser.cc. A remote attacker can create a specially crafted document, trick the victim into opening it, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Poppler
Amazon Linux AMI
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
openSUSE Leap
Ubuntu
libpoppler44
libpoppler44-debuginfo
poppler (Red Hat package)
libpoppler58 (Ubuntu package)
poppler-utils (Ubuntu package)
libpoppler-qt4-devel
libpoppler-qt4-4-debuginfo
libpoppler60-debuginfo
libpoppler-qt4-4
poppler-tools-debuginfo
libpoppler60
libpoppler-glib8-debuginfo
libpoppler-glib8
poppler-tools
libpoppler-cpp0-debuginfo
libpoppler-cpp0
poppler-debugsource
libpoppler-devel
libpoppler-glib-devel
typelib-1_0-Poppler-0_18
libpoppler73 (Ubuntu package)
libpoppler73-32bit-debuginfo
libpoppler73-32bit
libpoppler73
libpoppler73-debuginfo
evince (Red Hat package)

How to mitigate CVE-2018-21009

Install updates from vendor's website.

Poppler - update to 0.76.0
libpoppler44 - update to 0.24.4-14.26.1
libpoppler44-debuginfo - update to 0.24.4-14.26.1
poppler (Red Hat package) - update to 0.26.5-42.el7
libpoppler58 (Ubuntu package) - update to 0.41.0-0ubuntu1.15
poppler-utils (Ubuntu package) - addressed in versions 0.41.0-0ubuntu1.15, 0.62.0-2ubuntu2.11
libpoppler-qt4-devel - update to 0.43.0-16.25.1
libpoppler-qt4-4-debuginfo - update to 0.43.0-16.25.1
libpoppler60-debuginfo - update to 0.43.0-16.25.1
libpoppler-qt4-4 - update to 0.43.0-16.25.1
poppler-tools-debuginfo - update to 0.43.0-16.25.1
libpoppler60 - update to 0.43.0-16.25.1
libpoppler-glib8-debuginfo - update to 0.43.0-16.25.1
libpoppler-glib8 - update to 0.43.0-16.25.1
poppler-tools - update to 0.43.0-16.25.1
libpoppler-cpp0-debuginfo - update to 0.43.0-16.25.1
libpoppler-cpp0 - update to 0.43.0-16.25.1
poppler-debugsource - update to 0.43.0-16.25.1
libpoppler-devel - update to 0.43.0-16.25.1
libpoppler-glib-devel - update to 0.43.0-16.25.1
typelib-1_0-Poppler-0_18 - update to 0.43.0-16.25.1
libpoppler73 (Ubuntu package) - update to 0.62.0-2ubuntu2.11
libpoppler73-32bit-debuginfo - update to 0.62.0-150000.4.15.1
libpoppler73-32bit - update to 0.62.0-150000.4.15.1
libpoppler73 - update to 0.62.0-150000.4.15.1
libpoppler73-debuginfo - update to 0.62.0-150000.4.15.1
evince (Red Hat package) - update to 3.28.2-9.el7

External References

Related Security Bulletins