CVE-2017-14617: Input Validation
Published Sep 20, 2017
·Updated
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.
Affected Software
1 affected component
Freedesktop poppler=0.59.0
Event History
Sep 20, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14617?
CVE-2017-14617 has a severity rating that indicates a floating point exception vulnerability, which can be exploited through malicious PDF files.
2
How do I fix CVE-2017-14617?
To fix CVE-2017-14617, users should update Poppler to a version later than 0.59.0 that has addressed this vulnerability.
3
What software is affected by CVE-2017-14617?
CVE-2017-14617 specifically affects Poppler version 0.59.0.
4
What kind of attack can CVE-2017-14617 lead to?
CVE-2017-14617 may lead to potential attacks that exploit the floating point exception during the handling of malicious PDF files.
5
Is CVE-2017-14617 still a concern for my systems?
If your systems are running Poppler version 0.59.0 or earlier, CVE-2017-14617 remains a concern and should be mitigated.