cbcvebase.
CVE-2017-9776
published 2017-06-22

CVE-2017-9776: Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianpoppler< poppler 0.57.0-2 (bookworm)poppler 0.57.0-2 (bookworm)
freedesktoppoppler<= 0.55.0
freedesktoppoppler>= 0 < 0.57.0-20.57.0-2
freedesktoppoppler>= 0 < 0.57.0-20.57.0-2
freedesktoppoppler>= 0 < 0.57.0-20.57.0-2
freedesktoppoppler>= 0 < 0.57.0-20.57.0-2
freedesktoppoppler>= 0 < 0.24.5-2ubuntu4.70.24.5-2ubuntu4.7
freedesktoppoppler>= 0 < 0.41.0-0ubuntu1.40.41.0-0ubuntu1.4
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH