CVE-2017-1000456: Buffer Overflow
Published Jan 2, 2018
·Updated
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
Affected Software
5 affected componentsFixes available
debian/poppler
0.71.0-50.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
Freedesktop poppler=0.60.1
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Jan 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2017-1000456.
2
What is the severity level of CVE-2017-1000456?
The severity level of CVE-2017-1000456 is high (8.8).
3
What is the description of CVE-2017-1000456?
CVE-2017-1000456 is a vulnerability in freedesktop.org libpoppler 0.60.1 that fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
4
Which software versions are affected by CVE-2017-1000456?
The affected software versions include poppler 0.60.1, Debian Linux 7.0, Debian Linux 8.0, and Debian Linux 9.0.
5
How can I fix CVE-2017-1000456?
To fix CVE-2017-1000456, update the poppler package to version 0.71.0-5 or higher.