PT-2017-19231 · Poppler+2 · Poppler+2

Published

2017-06-25

·

Updated

2019-10-03

·

CVE-2017-9865

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Poppler version 0.54.0
Description The issue allows remote attackers to cause a denial of service, resulting in a stack-based buffer over-read and application crash, via a crafted PDF document. This is related to missing color-map validation.
Recommendations For Poppler version 0.54.0, consider updating to a newer version that includes the necessary validation to prevent the buffer over-read issue. As a temporary workaround, restrict the processing of crafted PDF documents to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9865
DLA-1074-1
DSA-4079-1
MGASA-2017-0276
MGASA-2017-0329
OPENSUSE-SU-2018_1721-1
SUSE-SU-2018:1662-1
USN-4042-1

Affected Products

Poppler
Suse
Ubuntu