A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:5305 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:9167 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-6239 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2293594 | patch third party advisory issue tracking |