Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18267

Опубликовано: 10 мая 2018
Источник: debian

Описание

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
popplerfixed0.65.0-1experimentalpackage
popplerfixed0.69.0-2package
popplerignoredwheezypackage

Примечания

  • https://bugs.freedesktop.org/show_bug.cgi?id=104942

  • https://bugs.freedesktop.org/show_bug.cgi?id=103238

  • https://cgit.freedesktop.org/poppler/poppler/commit/?id=60b4fe65bc9dc9b82bbadf0be2e3781be796a13d

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

CVSS3: 5.1
redhat
около 8 лет назад

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

CVSS3: 5.5
nvd
больше 7 лет назад

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

CVSS3: 5.5
github
больше 3 лет назад

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции FoFiType1C::cvtGlyph библиотеки для рендеринга PDF-файлов Poppler, связанная с бесконечной работой цикла, позволяющая нарушителю вызвать отказ в обслуживании