Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 670880 (CVE-2018-19149) - <app-text/poppler-0.70.0: Null pointer
Summary: <app-text/poppler-0.70.0: Null pointer
Alias: CVE-2018-19149
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Whiteboard: B3 [glsa+ cve]
Depends on: poppler-0.71.0 CVE-2018-20650
  Show dependency tree
Reported: 2018-11-11 02:10 UTC by Michael Boyle
Modified: 2019-04-02 04:22 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Michael Boyle 2018-11-11 02:10:15 UTC
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
Comment 1 Vlad K. 2018-11-11 12:39:48 UTC
* More info:

Gentoo Security Scout
Vladimir Krstulja
Comment 2 Vlad K. 2018-11-11 12:47:58 UTC
* Better URL, upstream issue

Gentoo Security Scout
Vladimir Krstulja
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2018-11-11 15:02:21 UTC
This has been fixed in 0.70.0
Comment 4 Andreas Sturmlechner gentoo-dev 2019-03-03 01:03:25 UTC
Cleanup done.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2019-04-02 04:22:52 UTC
This issue was resolved and addressed in
 GLSA 201904-04 at
by GLSA coordinator Aaron Bauman (b-man).