yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-6239
Component Overview
Vulnerability Overview
Name
CVE-2024-6239
Source
NVD (
link
)
Debian (
link
)
Description
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.
CWEs
CWE-20
Published Date
Jun 21, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/CVE-2024-6239
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2293594
Issue Tracking
https://access.redhat.com/security/cve/CVE-2024-6239
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2293594
Issue Tracking
Analysis
#
Affected Component
Analysis
poppler
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
poppler
buildroot
2025.02.x
25.10.0
Not Affected
poppler
buildroot
master
25.10.0
Not Affected
poppler
yocto
kirkstone
22.04.0
Patched
poppler
yocto
master
25.12.0
Not Affected
Resolved with patches
#
poppler (yocto:kirkstone)
#
Title
Author
Resolve
1
More unicode vectors; fewer raw pointers
Sune Vuorela <sune@vuorela.dk>
CVE-2024-6239
2
pdfinfo: Fix crash in broken documents when using -dests
Albert Astals Cid <aacid@kde.org>
CVE-2024-6239
poppler (yocto:scarthgap)
#
Title
Author
Resolve
1
More unicode vectors; fewer raw pointers
Sune Vuorela <sune@vuorela.dk>
CVE-2024-6239
2
pdfinfo: Fix crash in broken documents when using -dests
Albert Astals Cid <aacid@kde.org>
CVE-2024-6239