The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade popplerUpgrade xpdf | Jul 30, 2024 | Apr 18, 2008 |
| Gentoo Linux | — | Upgrade app-text/poppler. | Oct 30, 2017 | Apr 18, 2008 |
| Oracle_linux | — | Upgrade poppler-utilsUpgrade popplerUpgrade poppler-devel | Oct 16, 2024 | Apr 18, 2008 |
| Suse | — | Upgrade cups-clientUpgrade cups-libs-x86Upgrade cups-configUpgrade cups-ddkUpgrade cups-develUpgrade cups-libsUpgrade cupsUpgrade cups-libs-32bitUpgrade libcupsimage2Upgrade libcups2 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libpoppler1Upgrade kwordUpgrade libpoppler2 | Nov 8, 2024 | Apr 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub