CVE-2017-2820 — Integer Overflow or Wraparound in Poppler
Severity
8.8HIGHNVD
EPSS
1.7%
top 17.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 12
Latest updateMay 13
Description
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages3 packages
🔴Vulnerability Details
4GHSA▶
GHSA-2v7w-8gjr-q477: An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop↗2022-05-13
CVEList▶
CVE-2017-2820: An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop↗2017-07-12
OSV▶
CVE-2017-2820: An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop↗2017-07-12
📋Vendor Advisories
3💬Community
1Bugzilla
▶