CVE-2017-15565: Null Pointer Dereference
Published Oct 17, 2017
·Updated
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
Affected Software
5 affected componentsFixes available
debian/poppler
0.71.0-50.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
Freedesktop poppler=0.59.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Oct 17, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15565?
CVE-2017-15565 is assessed as a critical vulnerability due to the potential for exploitation through crafted PDF documents.
2
How do I fix CVE-2017-15565?
To fix CVE-2017-15565, update the Poppler package to versions 0.71.0-5 or newer.
3
What versions of Poppler are affected by CVE-2017-15565?
Poppler version 0.59.0 is affected by CVE-2017-15565.
4
Can CVE-2017-15565 lead to application crashes?
Yes, CVE-2017-15565 can cause application crashes due to a NULL pointer dereference.
5
Which operating systems are impacted by CVE-2017-15565?
CVE-2017-15565 impacts Debian Linux versions 7.0, 8.0, and 9.0 with the affected Poppler version.