CVE-2017-14929
Published: 29 September 2017
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.
Priority
CVSS 3 base score: 7.5
Status
Package | Release | Status |
---|---|---|
poppler Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was released [0.24.5-2ubuntu4.7])
|
|
xenial |
Released
(0.41.0-0ubuntu1.4)
|
|
zesty |
Released
(0.48.0-2ubuntu2.3)
|
|
Patches: upstream: https://cgit.freedesktop.org/poppler/poppler/commit/?id=2c92c7b6a828c9db8a38f079ea7a3d51c12a481d |