CVE-2017-14518: Input Validation
Published Sep 17, 2017
·Updated
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
Affected Software
2 affected componentsFixes available
debian/poppler
0.71.0-50.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
Freedesktop poppler=0.59.0
Event History
Sep 17, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14518?
CVE-2017-14518 has been classified as a high severity vulnerability due to its potential to cause a floating point exception in the Poppler library.
2
How do I fix CVE-2017-14518?
To fix CVE-2017-14518, upgrade Poppler to version 0.71.0-5 or later.
3
Which versions of Poppler are affected by CVE-2017-14518?
Poppler versions prior to 0.71.0, specifically version 0.59.0, are affected by CVE-2017-14518.
4
Is it safe to open PDFs with Poppler 0.59.0 after CVE-2017-14518?
It is not safe to open PDFs with Poppler 0.59.0, as it is vulnerable to a crafted PDF document causing a floating point exception.
5
What function is vulnerable in Poppler for CVE-2017-14518?
The vulnerable function in Poppler is isImageInterpolationRequired() located in Splash.cc.