CVE-2017-1000456Improper Restriction of Operations within the Bounds of a Memory Buffer in Poppler

Severity
8.8HIGHNVD
EPSS
0.7%
top 27.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 14

Description

freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Debianfreedesktop/poppler< 0.61.1-2+3
Ubuntufreedesktop/poppler< 0.24.5-2ubuntu4.9+1

Also affects: Debian Linux 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-54wv-g6q8-8695: freedesktop2022-05-14
OSV
poppler vulnerabilities2018-01-08
OSV
CVE-2017-1000456: freedesktop2018-01-02
CVEList
CVE-2017-1000456: freedesktop2018-01-02

📋Vendor Advisories

3
Ubuntu
poppler vulnerabilities2018-01-08
Red Hat
poppler: Invalid read in TextPool::addWord() causes crash and can lead to overflow in subsequent calculations2017-10-05
Debian
CVE-2017-1000456: poppler - freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addW...2017

💬Community

2
Bugzilla
CVE-2017-1000456 poppler: Invalid read in TextPool::addWord() causes crash and can lead to overflow in subsequent calculations2018-01-05
Bugzilla
CVE-2017-1000456 poppler: Invalid read in TextPool::addWord() causes crash and can lead to overflow in subsequent calculations [fedora-all]2018-01-05
CVE-2017-1000456 — Freedesktop Poppler vulnerability | cvebase