CVE-2017-14929: High severity Freedesktop poppler vulnerability
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14929?
CVE-2017-14929 has a high severity due to the potential for memory corruption and infinite loops in affected versions of Poppler.
What versions of Poppler are affected by CVE-2017-14929?
CVE-2017-14929 affects Poppler versions prior to 0.71.0, including version 0.59.0.
How do I fix CVE-2017-14929?
Fix CVE-2017-14929 by upgrading Poppler to version 0.71.0 or later.
What type of vulnerability is CVE-2017-14929?
CVE-2017-14929 is classified as a memory corruption vulnerability.
Is there a workaround for CVE-2017-14929?
There are currently no known effective workarounds for CVE-2017-14929; updating software is recommended.