CVE-2017-9408: Medium severity Freedesktop poppler vulnerability
Published Jun 2, 2017
·Updated
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
Affected Software
4 affected componentsFixes available
debian/poppler
0.71.0-50.71.0-5+deb10u320.09.0-3.1+deb11u122.12.0-2
Freedesktop poppler=0.54.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jun 2, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9408?
The severity of CVE-2017-9408 is rated as medium with a score of 6.5.
2
How do I fix CVE-2017-9408?
To fix CVE-2017-9408, upgrade to Poppler version 0.71.0-5 or later.
3
What software is affected by CVE-2017-9408?
CVE-2017-9408 affects Poppler version 0.54.0 and earlier versions on Debian Linux.
4
What is the impact of CVE-2017-9408?
CVE-2017-9408 allows attackers to cause a denial of service through a crafted file.
5
What function is vulnerable in CVE-2017-9408?
The vulnerability in CVE-2017-9408 is found in the function Object::initArray in Object.cc.