ALPINE-CVE-2020-35702

Source
https://security.alpinelinux.org/vuln/CVE-2020-35702
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2020-35702.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALPINE-CVE-2020-35702
Upstream
Published
2020-12-25T02:15:12.900Z
Modified
2026-03-09T01:19:12.904032Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects

References

Affected packages

Alpine:v3.13 / poppler

Package

Name
poppler
Purl
pkg:apk/alpine/poppler?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2020-35702.json"