Vulnerability Description
A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
CVSS Score
6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freedesktop | Poppler | 22.07.0 |
Related Weaknesses (CWE)
References
- https://gitlab.freedesktop.org/poppler/poppler/-/commit/8677500399fc2548fa816b61Patch
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1278ExploitIssue Tracking
- https://gitlab.freedesktop.org/poppler/poppler/-/commit/8677500399fc2548fa816b61Patch
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1278ExploitIssue Tracking
- https://lists.debian.org/debian-lts-announce/2025/04/msg00037.html
FAQ
What is CVE-2022-37052?
CVE-2022-37052 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
How severe is CVE-2022-37052?
CVE-2022-37052 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-37052?
Check the references section above for vendor advisories and patch information. Affected products include: Freedesktop Poppler.