在由 Innodata Labs 开发的 Poppler 分支的内部 JPEG2000(JPX)解码实现中存在拒绝服务(DoS)漏洞。当应用程序处理包含特殊构造的 JPXDecode 图像的不可信 PDF 文件时,远程攻击者可导致不受控制的内存消耗。该缺陷出现在 JPXStream::readCodestream() 函数中,来自 SIZ 段(例如 img.nComps)的、由外部控制的数据被用于分配瓦片(tiles)和分量(components)的内存,但未进行充分的验证。攻击者可借此迫使系统过度分配内存,从而导
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Poppler | Innodata Labs | 0 ~ 25/08/2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet