CVE-2017-2820Integer Overflow or Wraparound in Poppler

Severity
8.8HIGHNVD
EPSS
1.7%
top 17.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 12
Latest updateMay 13

Description

An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Ubuntufreedesktop/poppler< 0.24.5-2ubuntu4.5+1
CVEListV5poppler/poppler0.53

🔴Vulnerability Details

4
GHSA
GHSA-2v7w-8gjr-q477: An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop2022-05-13
CVEList
CVE-2017-2820: An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop2017-07-12
OSV
CVE-2017-2820: An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop2017-07-12
OSV
poppler vulnerabilities2017-07-07

📋Vendor Advisories

3
Red Hat
poppler: Integer overflow in the JPEG 2000 image parsing functionality2017-07-07
Ubuntu
poppler vulnerabilities2017-07-07
Debian
CVE-2017-2820: poppler - An exploitable integer overflow vulnerability exists in the JPEG 2000 image pars...2017

💬Community

1
Bugzilla
CVE-2017-2820 poppler: Integer overflow in the JPEG 2000 image parsing functionality2017-07-12
CVE-2017-2820 — Integer Overflow or Wraparound | cvebase