CVE-2017-14520: Input Validation
Published Sep 17, 2017
·Updated
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
Affected Software
2 affected componentsFixes available
debian/poppler
0.71.0-50.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
Freedesktop poppler=0.59.0
Event History
Sep 17, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14520?
CVE-2017-14520 has a severity that can lead to a potential attack due to a floating point exception in Poppler when processing malicious PDF files.
2
How do I fix CVE-2017-14520?
To fix CVE-2017-14520, upgrade Poppler to versions 0.71.0-5 or later, as well as any specific patch releases from Debian.
3
Which versions of Poppler are affected by CVE-2017-14520?
CVE-2017-14520 affects Poppler version 0.59.0 and earlier versions.
4
What kind of exploit is associated with CVE-2017-14520?
CVE-2017-14520 is associated with a potential attack that may be executed through maliciously crafted PDF files.
5
Is CVE-2017-14520 a denial-of-service vulnerability?
Yes, CVE-2017-14520 could be exploited to trigger a denial-of-service condition due to the floating point exception in Poppler.