CVE-2017-18267: Medium severity Freedesktop poppler vulnerability
Published May 10, 2018
·Updated
Last updated 25 August 2025
Other sources
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
— Launchpad
Affected Software
11 affected componentsFixes available
Freedesktop poppler<=0.64.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
redhat Ansible Tower=3.3
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Debian Debian Linux=8.0
debian/poppler
20.09.0-3.1+deb11u120.09.0-3.1+deb11u222.12.0-2+deb12u125.03.0-5+deb13u225.03.0-11.1
Remediation
Event History
May 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
May 16, 2018
Data Sourced
via Red Hat·11:47 AM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:36 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·10:17 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:17 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-18267.
2
What is the severity of CVE-2017-18267?
The severity of CVE-2017-18267 is medium.
3
What software is affected by CVE-2017-18267?
Poppler through 0.64.0 is affected by CVE-2017-18267.
4
How can remote attackers exploit CVE-2017-18267?
Remote attackers can exploit CVE-2017-18267 by sending a crafted PDF file, leading to a denial of service (infinite recursion).
5
How can I fix CVE-2017-18267?
To fix CVE-2017-18267, update Poppler to version 0.71.0-5 or later.