CVE-2017-14519: High severity poppler data vulnerability
Published Sep 17, 2017
·Updated
In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop).
Affected Software
2 affected componentsFixes available
debian/poppler
0.71.0-50.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
Freedesktop poppler=0.59.0
Event History
Sep 17, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14519?
CVE-2017-14519 is classified as a memory corruption vulnerability that can lead to potential security risks.
2
How do I fix CVE-2017-14519?
To fix CVE-2017-14519, upgrade to Poppler version 0.71.0-5 or later.
3
Which versions of Poppler are affected by CVE-2017-14519?
CVE-2017-14519 affects Poppler version 0.59.0.
4
What type of software is impacted by CVE-2017-14519?
CVE-2017-14519 impacts the Poppler PDF rendering library.
5
What kind of attack can exploit CVE-2017-14519?
CVE-2017-14519 can be exploited through crafted PDF files that trigger the vulnerability during rendering.