CVE-2019-9631: Debian Linux
Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
- Freedesktop Poppler: version 0.74.0 only
Published 2019-03-08. Last modified 2026-06-17.