Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-14517

Published: 17 September 2017

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

Notes

AuthorNote
leosilva
couldn't reproduce in trusty or xenial using POC

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
poppler
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist
(trusty was not-affected [not reproducible])
upstream Needs triage

xenial Not vulnerable
(not reproducible)
zesty
Released (0.48.0-2ubuntu2.2)
Patches:
upstream: https://cgit.freedesktop.org/poppler/poppler/commit/?id=476394e7a025e02e4897da2e765df2c895d0708f