Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9865

Опубликовано: 25 июн. 2017
Источник: debian
EPSS Низкий

Описание

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
popplerfixed0.57.0-2package

Примечания

  • https://bugs.freedesktop.org/show_bug.cgi?id=100774

  • http://somevulnsofadlab.blogspot.com/2017/06/popplerstack-buffer-overflow-in.html

  • Fixed by: https://cgit.freedesktop.org/poppler/poppler/commit/?id=75fff6556eaf0ef3a6fcdef2c2229d0b6d1c58d9

EPSS

Процентиль: 73%
0.0076
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.

CVSS3: 3.3
redhat
почти 9 лет назад

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.

CVSS3: 5.5
nvd
больше 8 лет назад

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.

CVSS3: 5.5
github
больше 3 лет назад

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.

suse-cvrf
больше 7 лет назад

Security update for poppler

EPSS

Процентиль: 73%
0.0076
Низкий