First published: Sat Sep 30 2017(Updated: )
In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Data | =0.59.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14927 is classified as a medium severity vulnerability due to the potential for denial-of-service attacks.
To fix CVE-2017-14927, upgrade Poppler to version 0.60.0 or later.
CVE-2017-14927 can lead to a NULL pointer dereference causing application crashes when processing specially crafted PDF files.
Anyone using Poppler version 0.59.0 is potentially affected by CVE-2017-14927.
CVE-2017-14927 can be exploited remotely if a victim opens a malicious PDF document.