Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14977

Опубликовано: 02 окт. 2017
Источник: debian
EPSS Низкий

Описание

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
popplerfixed0.61.1-2package

Примечания

  • https://bugs.freedesktop.org/show_bug.cgi?id=103045

  • https://cgit.freedesktop.org/poppler/poppler/commit/?id=19eedc6fb693a62f305e13079501e3105f869f3c

EPSS

Процентиль: 78%
0.01097
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

CVSS3: 3.3
redhat
больше 8 лет назад

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

CVSS3: 7.5
nvd
больше 8 лет назад

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

CVSS3: 7.5
github
больше 3 лет назад

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

suse-cvrf
больше 7 лет назад

Security update for poppler

EPSS

Процентиль: 78%
0.01097
Низкий