
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability identified as CVE-2020-36024 was discovered in freedesktop poppler version 20.12.1. The vulnerability allows remote attackers to cause a denial of service (DoS) through a crafted PDF file targeting the FoFiType1C::convertToType1 function (NVD, Debian LTS).
The vulnerability is a NULL pointer dereference issue in the FoFiType1C::convertToType1 function. The bug occurs when enc == 0 at line 304 of the function, leading to a potential crash. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD, Gitlab Issue).
When exploited, the vulnerability can cause a denial of service condition through application crashes due to the NULL pointer dereference. This affects systems using the poppler PDF rendering library, potentially disrupting PDF processing capabilities (NVD).
Multiple distributions have released patches to address this vulnerability. Debian has fixed the issue in version 0.71.0-5+deb10u2 for Debian 10 (Buster). Ubuntu has also provided fixes for various versions including 20.04 LTS (focal), 18.04 LTS (bionic), and other supported releases (Debian LTS, Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."