Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
{ "vanir_signatures": [ { "deprecated": false, "id": "CVE-2018-21009-48bf8395", "signature_version": "v1", "digest": { "line_hashes": [ "154375407315414143549880905028037258126", "82182342157428160508916575157957765478", "264751418982462844016162579247917897248", "64969021713010401978135441366154185423", "213486778590520558100284425021732335989" ], "threshold": 0.9 }, "signature_type": "Line", "target": { "file": "poppler/Parser.cc" }, "source": "https://gitlab.freedesktop.org/poppler/poppler@0868c499a9f5f37f8df5c9fef03c37496b40fc8a" }, { "deprecated": false, "id": "CVE-2018-21009-c803942f", "signature_version": "v1", "digest": { "length": 1657.0, "function_hash": "112702152531844563030401939967697747850" }, "signature_type": "Function", "target": { "function": "Parser::makeStream", "file": "poppler/Parser.cc" }, "source": "https://gitlab.freedesktop.org/poppler/poppler@0868c499a9f5f37f8df5c9fef03c37496b40fc8a" } ] }