CVE-2017-9865: Medium severity poppler data vulnerability
Last updated 24 July 2024
Other sources
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9865?
The severity of CVE-2017-9865 is medium.
How does CVE-2017-9865 affect Poppler?
CVE-2017-9865 affects Poppler version 0.54.0.
How can remote attackers exploit CVE-2017-9865?
Remote attackers can exploit CVE-2017-9865 by sending a crafted PDF document to the affected system.
Is there a fix available for CVE-2017-9865?
Yes, a fix is available for CVE-2017-9865. It is recommended to upgrade to version 0.71.0-5 or higher.
Where can I find more information about CVE-2017-9865?
More information about CVE-2017-9865 can be found at the following references: [Link 1](http://somevulnsofadlab.blogspot.com/2017/06/popplerstack-buffer-overflow-in.html), [Link 2](https://bugs.freedesktop.org/show_bug.cgi?id=100774), [Link 3](https://www.debian.org/security/2018/dsa-4079).