CVE-2024-6239

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

12 Nov 2024, 17:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:9167 -

16 Aug 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:5305 -

24 Jun 2024, 19:06

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.5
First Time Freedesktop
Redhat enterprise Linux
Redhat
Freedesktop poppler
Summary
  • (es) Se encontró una falla en la utilidad Pdfinfo de Poppler. Este problema ocurre cuando se usa el parámetro -dests con la utilidad pdfinfo. Al utilizar ciertos archivos de entrada con formato incorrecto, un atacante podría provocar que la utilidad fallara, lo que provocaría una denegación de servicio.
References () https://access.redhat.com/security/cve/CVE-2024-6239 - () https://access.redhat.com/security/cve/CVE-2024-6239 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2293594 - () https://bugzilla.redhat.com/show_bug.cgi?id=2293594 - Issue Tracking, Patch, Third Party Advisory
CPE cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*

21 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-21 14:15

Updated : 2024-11-12 17:15


NVD link : CVE-2024-6239

Mitre link : CVE-2024-6239

CVE.ORG link : CVE-2024-6239


JSON object : View

Products Affected

freedesktop

  • poppler

redhat

  • enterprise_linux
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation