CVE-2019-9200

Publication date 26 February 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Description

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

Status

Package Ubuntu Release Status
poppler 19.04 disco
Fixed 0.74.0-0ubuntu1.2
18.10 cosmic
Fixed 0.68.0-0ubuntu1.6
18.04 LTS bionic
Fixed 0.62.0-2ubuntu2.8
16.04 LTS xenial
Fixed 0.41.0-0ubuntu1.13
14.04 LTS trusty
Fixed 0.24.5-2ubuntu4.17

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
poppler

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.8 · High

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities