CVE-2013-7296

medium
Published 2014-01-26 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted PDF file.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debiantrixiefixed0
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0

Application impact

VendorProductVersionsFixed
freedesktoppoppler{"endIncluding":"0.24.3"}
freedesktoppoppler0.1
freedesktoppoppler0.1.1
freedesktoppoppler0.1.2
freedesktoppoppler0.2.0
freedesktoppoppler0.10.0
freedesktoppoppler0.10.1
freedesktoppoppler0.10.2
freedesktoppoppler0.10.3
freedesktoppoppler0.10.4
freedesktoppoppler0.10.5
freedesktoppoppler0.10.6
freedesktoppoppler0.10.7
freedesktoppoppler0.11.0
freedesktoppoppler0.11.1
freedesktoppoppler0.11.2
freedesktoppoppler0.11.3
freedesktoppoppler0.12.0
freedesktoppoppler0.12.1
freedesktoppoppler0.12.2
freedesktoppoppler0.12.3
freedesktoppoppler0.12.4
freedesktoppoppler0.13.0
freedesktoppoppler0.13.1
freedesktoppoppler0.13.2
freedesktoppoppler0.13.3
freedesktoppoppler0.13.4
freedesktoppoppler0.14.0
freedesktoppoppler0.14.1
freedesktoppoppler0.14.2
freedesktoppoppler0.14.3
freedesktoppoppler0.14.4
freedesktoppoppler0.14.5
freedesktoppoppler0.15.0
freedesktoppoppler0.15.1
freedesktoppoppler0.15.2
freedesktoppoppler0.15.3
freedesktoppoppler0.16.0
freedesktoppoppler0.16.1
freedesktoppoppler0.16.2
freedesktoppoppler0.16.3
freedesktoppoppler0.16.4
freedesktoppoppler0.16.5
freedesktoppoppler0.16.6
freedesktoppoppler0.16.7
freedesktoppoppler0.17.0
freedesktoppoppler0.17.1
freedesktoppoppler0.17.2
freedesktoppoppler0.17.3
freedesktoppoppler0.17.4
freedesktoppoppler0.18.0
freedesktoppoppler0.18.1
freedesktoppoppler0.18.2
freedesktoppoppler0.18.3
freedesktoppoppler0.18.4
freedesktoppoppler0.19.0
freedesktoppoppler0.19.1
freedesktoppoppler0.19.2
freedesktoppoppler0.19.3
freedesktoppoppler0.19.4
freedesktoppoppler0.20.0
freedesktoppoppler0.20.1
freedesktoppoppler0.20.2
freedesktoppoppler0.20.3
freedesktoppoppler0.20.4
freedesktoppoppler0.20.5
freedesktoppoppler0.21.0
freedesktoppoppler0.21.1
freedesktoppoppler0.21.2
freedesktoppoppler0.21.3
freedesktoppoppler0.21.4
freedesktoppoppler0.22.0
freedesktoppoppler0.22.1
freedesktoppoppler0.22.2
freedesktoppoppler0.22.3
freedesktoppoppler0.22.4
freedesktoppoppler0.23.0
freedesktoppoppler0.23.1
freedesktoppoppler0.23.2
freedesktoppoppler0.23.3
freedesktoppoppler0.23.4
freedesktoppoppler0.24.0
freedesktoppoppler0.24.1
freedesktoppoppler0.24.2

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.