CVE-2017-9776: Integer Overflow
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
Other sources
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in Poppler allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
Upstream issue:
https://bugs.freedesktop.org/showbug.cgi?id=101541
Upstream patch:
https://cgit.freedesktop.org/poppler/poppler/commit/?id=a3a98a6d83dfbf49f565f5aa2d7c07153a7f62fc
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9776?
CVE-2017-9776 has been classified as a vulnerability with the potential to cause a denial of service and possibly other unspecified impacts.
How do I fix CVE-2017-9776?
To fix CVE-2017-9776, update the Poppler package to versions 0.71.0-5 or later, as recommended by your operating system vendor.
What type of vulnerability is CVE-2017-9776?
CVE-2017-9776 is an integer overflow vulnerability that leads to a heap buffer overflow.
Which software is affected by CVE-2017-9776?
CVE-2017-9776 affects versions of the Poppler library prior to 0.56, and various distributions of Debian and Red Hat Enterprise Linux.
Can CVE-2017-9776 be exploited remotely?
Yes, CVE-2017-9776 can be exploited remotely through a crafted PDF document.