{"id":"CVE-2022-37050","details":"In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.","modified":"2026-08-12T13:32:09.478269Z","published":"2023-08-22T00:00:00Z","related":["SUSE-SU-2023:3947-1","SUSE-SU-2023:3981-1","SUSE-SU-2023:3982-1","SUSE-SU-2023:3983-1","SUSE-SU-2023:3998-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37050.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00037.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37050.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37050"},{"type":"REPORT","url":"https://gitlab.freedesktop.org/poppler/poppler/-/issues/1274"},{"type":"FIX","url":"https://gitlab.freedesktop.org/poppler/poppler/-/commit/dcd5bd8238ea448addd102ff045badd0aca1b990"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/poppler/poppler","events":[{"introduced":"bb1651334abc11495fa0326c8d562243d2a4b055"},{"fixed":"dcd5bd8238ea448addd102ff045badd0aca1b990"}],"database_specific":{"cpe":"cpe:2.3:a:freedesktop:poppler:22.07.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"22.07.0"},{"last_affected":"22.07.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["22.07.0","poppler-22.07.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37050.json","vanir_signatures_modified":"2026-08-12T13:32:09Z","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["114842602092432893778271834459282916621","106906025405781008382997333553472705956","297354338754434299385182409393809636327","326917231957895818469694738405259608057"]},"id":"CVE-2022-37050-2688e38d","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/poppler/poppler@dcd5bd8238ea448addd102ff045badd0aca1b990","target":{"file":"poppler/PDFDoc.cc"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"233931809287936889414848428528741274552","length":5212},"id":"CVE-2022-37050-b72075c3","signature_type":"Function","signature_version":"v1","source":"https://gitlab.freedesktop.org/poppler/poppler@dcd5bd8238ea448addd102ff045badd0aca1b990","target":{"file":"poppler/PDFDoc.cc","function":"PDFDoc::savePageAs"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}