Bugzilla – Bug 1202698
VUL-0: CVE-2022-33108: poppler: a stack overflow vulnerability via the Object:Copy class of object.cc
Last modified: 2022-08-29 10:40:20 UTC
rh#2103120 XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. https://forum.xpdfreader.com/viewtopic.php?f=3&t=42284 https://forum.xpdfreader.com/viewtopic.php?f=3&t=42286 https://forum.xpdfreader.com/viewtopic.php?f=3&t=42287 References: https://bugzilla.redhat.com/show_bug.cgi?id=2103120 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-33108 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-33108 https://forum.xpdfreader.com/viewtopic.php?f=3&t=42284 https://forum.xpdfreader.com/viewtopic.php?f=3&t=42286 https://forum.xpdfreader.com/viewtopic.php?f=3&t=42287
The fix will be in xpdf 4.05, lets wait for that.
Okay, nevermind I could not reproduce this with the latest poppler version (6b5437a07535d5fd07c114e71c2cbff9b2a2f454), so I would close this as not affected.
Created attachment 861163 [details] poc