| Summary: | PDF Deflate bombs may cause crashes or resource exhaustion | ||
|---|---|---|---|
| Product: | [Applications] okular | Reporter: | Jens Mueller <jens.a.mueller+kde> |
| Component: | PDF backend | Assignee: | Okular developers <okular-devel> |
| Status: | RESOLVED UPSTREAM | ||
| Severity: | normal | CC: | aacid, nate, postix |
| Priority: | NOR | ||
| Version First Reported In: | 1.3.3 | ||
| Target Milestone: | --- | ||
| Platform: | Other | ||
| OS: | Linux | ||
| Latest Commit: | Version Fixed/Implemented In: | ||
| Sentry Crash Report: | |||
| Attachments: |
Trivial PDF deflate bomb (01)
Trivial PDF deflate bomb (02) Trivial PDF deflate bomb (03) |
||
|
Description
Jens Mueller
2020-01-23 16:38:10 UTC
Created attachment 125332 [details]
Trivial PDF deflate bomb (01)
Created attachment 125333 [details]
Trivial PDF deflate bomb (02)
Created attachment 125334 [details]
Trivial PDF deflate bomb (03)
Okular doesn't do any pdf parsing. Please report upstream at poppler. I opened an issue for Poppler: https://gitlab.freedesktop.org/poppler/poppler/issues/878 If it's handled there, things should be fine. |