CVE-2015-8868
06.05.2016, 17:59
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| freedesktop | poppler | 0.39.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| libpoppler-glib8 |
| ||||||||
| libpoppler-qt4-4 |
| ||||||||
| libpoppler44 |
| ||||||||
| poppler-tools |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| poppler |
| ||
| poppler-cpp |
| ||
| poppler-cpp-devel |
| ||
| poppler-demos |
| ||
| poppler-devel |
| ||
| poppler-glib |
| ||
| poppler-glib-devel |
| ||
| poppler-qt |
| ||
| poppler-qt-devel |
| ||
| poppler-utils |
|
Common Weakness Enumeration
References