Our takeCERT-Bund updated its advisory on a code-execution flaw in poppler that a local attacker can exploit. Update if you run it yourself.Cyber Resilience desk
Sources (1)
- cert_bund · cert_bund
What this means for you — Security leader:CERT-Bund confirmed a code-execution flaw in poppler that a local attacker can trigger. Update poppler on every system where it is installed.
What this means for you — Lean IT orgs:A local attacker can run code by exploiting a flaw in poppler. Update it now if you run any software that uses poppler (for example certain PDF viewers or office tools).
What this means for you — MSP:CERT-Bund confirmed a code-execution vulnerability in poppler (local attacker). Check every client for poppler usage and ensure the latest version is deployed.
What this means for you — Researcher:CERT-Bund confirmed a local code-execution vulnerability in poppler. Update if you run it yourself.