Security Advisory

CVE-2019-9959

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-22 14:18:19
Last updated 2024-08-04 22:10:08
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.