#VU16350 Out-of-bounds read in Poppler - CVE-2018-19059
Published: December 10, 2018
Poppler
Freedesktop.org
Description
The vulnerability allows a remote attacker to cause DoS condicion on the target system.
The vulnerability exists due to out-of-bounds read condition in the EmbFile::save2 function, as defined in the FileSpec.cc source code file after insufficient validation of embedded files before save attempts. A remote attacker can trick the victim into accessing an embedded file that submits malicious input, trigger out-of-bounds read condition and cause the service to crash.