Bug#1010695: poppler: CVE-2022-27337: Logic error in function Hints::Hints

Salvatore Bonaccorso carnil at debian.org
Sat May 7 16:02:30 BST 2022


Source: poppler
Version: 22.02.0-3
Severity: important
Tags: security upstream
Forwarded: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1230
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerability was published for poppler.

CVE-2022-27337[0]:
| A logic error in the Hints::Hints function of Poppler v22.03.0 allows
| attackers to cause a Denial of Service (DoS) via a crafted PDF file.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-27337
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27337
[1] https://gitlab.freedesktop.org/poppler/poppler/-/issues/1230
[2] https://gitlab.freedesktop.org/poppler/poppler/-/commit/81044c64b9ed9a10ae82a28bac753060bdfdac74

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-freedesktop-maintainers mailing list