CVE-2017-14927: Null Pointer Dereference
Published Sep 29, 2017
·Updated
In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.
Affected Software
1 affected component
Freedesktop poppler=0.59.0
Event History
Sep 29, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14927?
CVE-2017-14927 is classified as a medium severity vulnerability due to the potential for denial-of-service attacks.
2
How do I fix CVE-2017-14927?
To fix CVE-2017-14927, upgrade Poppler to version 0.60.0 or later.
3
What impact does CVE-2017-14927 have on my system?
CVE-2017-14927 can lead to a NULL pointer dereference causing application crashes when processing specially crafted PDF files.
4
Who is affected by CVE-2017-14927?
Anyone using Poppler version 0.59.0 is potentially affected by CVE-2017-14927.
5
Is CVE-2017-14927 exploitable remotely?
CVE-2017-14927 can be exploited remotely if a victim opens a malicious PDF document.