Poppler 0.42.0 至 26.10.0 版本中存在一个栈缓冲区溢出漏洞,位于 Decrypt::revision6Hash() 函数中。当打开使用 AES-V3/R6 加密的 PDF 文件时,攻击者若能控制密码,即可覆盖栈内存。攻击者可通过使用 libpoppler、libpoppler-glib 或 C++ API 的应用程序,提供长度超过 127 字节的密码,从而溢出 K1 和 E 缓冲区,导致进程崩溃或内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| freedesktop | poppler | 0.42.0 ~ 26.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet