Uncontrolled Recursion has been discovered in pdfinfo and pdftops in version 0.89.0 of the Poppler PDF rendering library ( CVE-2020-23804 ). This severe stack overflow vulnerability, which has received a National Vulnerability Database base score of 7.5 out of 10, significantly threatens the availability of impacted systems. . This flaw allows remote attackers to cause a denial of service via crafted input, leading to loss of system access. Important updates for Poppler have been released to mitigate this severe flaw. Given this bug’s significant impact on affected systems, if left unpatched, we strongly recommend all impacted users apply the updates released by their distro(s) immediately to prevent inconvenient, costly downtime and protect access to their critical systems. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . This vulnerability enables distant intruders to trigger a denial of service through specially crafted data, resulting in the loss of essential access.. Denial Of Service, Poppler Update, Stack Overflow, Security Patch, System Access. . Brittany Day
Two remotely exploitable security flaws involving incorrect handling of certain malformed PDF files were discovered in the Poppler PDF rendering library ( CVE-2020-36023 and CVE-2020-36024 ). These vulnerabilities could result in crashes leading to denial of service (DoS). . Updates for Poppler that mitigate these issues are now available. We strongly recommend that all impacted users apply the updates issued by Debian LTS , Mageia , and Ubuntu as soon as possible to protect against loss of access to critical systems. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . New patches for Poppler have been issued to mitigate severe vulnerabilities leading to system crashes and downtime. Ensure your environments are updated immediately.. Poppler Update, DoS Mitigation, Security Flaws, PDF Rendering, Open Source. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.