A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
[ { "signature_type": "Function", "id": "CVE-2022-37052-357399da", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "function": "PDFDoc::markPageObjects", "file": "poppler/PDFDoc.cc" }, "digest": { "function_hash": "273756925730686209409700961054074407743", "length": 709.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2022-37052-4f2dcdba", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "file": "poppler/PDFDoc.h" }, "digest": { "threshold": 0.9, "line_hashes": [ "304763745735970609053420384128652229620", "285734504008593386344482617858104492461", "42814253859592019564684101588992511544", "144475224911350134147774134213851618754", "302150748859724529365661420478494794355", "141952162578584534771931153988567791394", "55032832115138834537295743468745718799", "122822177716706062952169414778322927427", "283465543101396804212134638422795166818" ] }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2022-37052-64302f1f", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "file": "poppler/XRef.cc" }, "digest": { "threshold": 0.9, "line_hashes": [ "134096156516675972427431398213772276121", "274327033565891089251809362098007404131", "315657861017043028439752118736779152135", "310342747494632308086225423428618839521", "92396259489956248320603010373259439083", "270520818532505959051670855695497686081", "335881736725917897195697873099055027697", "164051132287074236309229571548028521310", "17751297525307814789131837797628208146", "189875661574654780375141035586907846394", "213309912279115776104064918058018866003", "16644388870974947084726191627353839288", "268571084823426447010581855078239765394" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2022-37052-8ffc8827", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "function": "XRef::add", "file": "poppler/XRef.cc" }, "digest": { "function_hash": "265854075833851323163455858885360079047", "length": 755.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2022-37052-93c1b8f8", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "file": "poppler/PDFDoc.cc" }, "digest": { "threshold": 0.9, "line_hashes": [ "181121801735472870747064168897293064753", "103849804712730882272502648342367527431", "238488805745295518063374455616277696956", "42472909311302188098805619784000013506", "233625066270574834955011569576312928500", "75664786433942053680026097669574713992", "208805775242167726415995853162192219040", "220419883820348326307039946341742938338", "61917267004015817643902586948065351305", "27572075541360334951639378527805457552", "99684671619090908489545030726255953084", "52085140924174949520070855027186660109", "223282412741190902309740621689792284853", "129670537360838863992555275225918931522", "189898027770441618091137947380505481845", "155724131685714179047106032279560313762", "280443418261585862621500037940357628307", "128533887594667786220787234371560225452", "67554265527797244414600859092524701792", "165905509614342909963765556899922535079", "189097498935229262449799936105367639560", "328419242371765894953879174147444856717", "317744966017308072460218150903663715071", "2549616002819190507008590709287207674", "30226865350122731700804720227653342594", "272658899906436141828822551123325982566", "27343171998904660719693444792653983257", "83503353470314851440885292692948855136", "204436595130037764209191444383447967278", "71252050461489719397117453546589931510", "156743346432394965577988407921567885326", "139679651120162827735461154894157803893", "151319260573666554332746136901352437216", "30244300537274772668835953786996295150", "284687237492628172687858486892651723074", "86377232768167425300079074237041194041", "294294628017295352111398640826199048262", "79218594291237834113755572816588569840", "138513904318935184400684750115748454881", "57979830787349977242382780301315612918", "86137282764665669728078980229957090349", "109013260683642739482036434946018413875", "20462608885410098888274097433398959874", "197853115046528317048296470900160406832", "86061556003459992339770577003785653667", "207266259933894148082571856406029033097", "163365333947463192760216260292028193514", "80999898128383754846637531388484076267", "230963802312648301743951661835500237537", "206889750627986001176721596177602803727", "148896266642754693014410053401126105406", "3082988167326356478324557029362217157", "164424615629908906161001745480727266069", "197071821099192885370360213041544098611", "286732353364019643233002812980868526469", "283751313876690936838764259348357802012", "41071853850630745773623740120608693682", "112519370760921898887447722393055300814", "168050689144898433988163632553986462528" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2022-37052-97ac3fed", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "function": "PDFDoc::savePageAs", "file": "poppler/PDFDoc.cc" }, "digest": { "function_hash": "197304028110258360728833384447789571097", "length": 5396.0 }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2022-37052-c7cf7770", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "function": "PDFDoc::markDictionnary", "file": "poppler/PDFDoc.cc" }, "digest": { "function_hash": "306958588208927882981585762373439715062", "length": 905.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2022-37052-d0da06e1", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "file": "poppler/XRef.h" }, "digest": { "threshold": 0.9, "line_hashes": [ "310548202309649677640359435006934084069", "190936668863168266132341448049422773006", "107772950137501725646981282321080987592", "209758221373415250500470014251972493500", "83092231472203693719898975207936840575" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2022-37052-d7e5e735", "source": "https://gitlab.freedesktop.org/poppler/poppler@8677500399fc2548fa816b619580c2c07915a98c", "signature_version": "v1", "target": { "function": "PDFDoc::markObject", "file": "poppler/PDFDoc.cc" }, "digest": { "function_hash": "260898325034261758350243020121820767480", "length": 1764.0 }, "deprecated": false } ]