4.3
CVSSv2

CVE-2017-7511

Published: 30/05/2017 Updated: 18/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler 0.54.0

freedesktop poppler 0.53.0

freedesktop poppler 0.52.0

freedesktop poppler 0.45.0

freedesktop poppler 0.44.0

freedesktop poppler 0.37.0

freedesktop poppler 0.36.0

freedesktop poppler 0.28.1

freedesktop poppler 0.28.0

freedesktop poppler 0.25.3

freedesktop poppler 0.25.2

freedesktop poppler 0.24.1

freedesktop poppler 0.24.0

freedesktop poppler 0.22.3

freedesktop poppler 0.22.2

freedesktop poppler 0.21.0

freedesktop poppler 0.20.5

freedesktop poppler 0.19.3

freedesktop poppler 0.19.2

freedesktop poppler 0.17.4

freedesktop poppler 0.17.3

freedesktop poppler 0.55.0

freedesktop poppler 0.47.0

freedesktop poppler 0.46.0

freedesktop poppler 0.39.0

freedesktop poppler 0.38.0

freedesktop poppler 0.31.0

freedesktop poppler 0.30.0

freedesktop poppler 0.49.0

freedesktop poppler 0.48.0

freedesktop poppler 0.41.0

freedesktop poppler 0.40.0

freedesktop poppler 0.33.0

freedesktop poppler 0.32.0

freedesktop poppler 0.29.0

freedesktop poppler 0.26.1

freedesktop poppler 0.26.0

freedesktop poppler 0.24.3

freedesktop poppler 0.24.2

freedesktop poppler 0.22.5

freedesktop poppler 0.22.4

freedesktop poppler 0.21.2

freedesktop poppler 0.21.1

freedesktop poppler 0.20.0

freedesktop poppler 0.19.4

freedesktop poppler 0.18.1

freedesktop poppler 0.18.0

freedesktop poppler 0.26.3

freedesktop poppler 0.26.2

freedesktop poppler 0.24.5

freedesktop poppler 0.24.4

freedesktop poppler 0.23.2

freedesktop poppler 0.23.1

freedesktop poppler 0.23.0

freedesktop poppler 0.21.4

freedesktop poppler 0.21.3

freedesktop poppler 0.20.2

freedesktop poppler 0.20.1

freedesktop poppler 0.18.3

freedesktop poppler 0.18.2

freedesktop poppler 0.51.0

freedesktop poppler 0.50.0

freedesktop poppler 0.43.0

freedesktop poppler 0.42.0

freedesktop poppler 0.35.0

freedesktop poppler 0.34.0

freedesktop poppler 0.26.5

freedesktop poppler 0.26.4

freedesktop poppler 0.25.1

freedesktop poppler 0.25.0

freedesktop poppler 0.23.4

freedesktop poppler 0.23.3

freedesktop poppler 0.22.1

freedesktop poppler 0.22.0

freedesktop poppler 0.20.4

freedesktop poppler 0.20.3

freedesktop poppler 0.19.1

freedesktop poppler 0.19.0

freedesktop poppler 0.18.4

Vendor Advisories

poppler could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #865679 poppler: CVE-2017-9776: integer overflow leading to heap buffer overflow in JBIG2Streamcc via a crafted PDF document Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso ...
Debian Bug report logs - #863759 poppler: CVE-2017-7511 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 31 May 2017 06:09:02 UTC Severity: normal Tags: fixed-u ...
Debian Bug report logs - #867477 poppler: CVE-2017-9865 stack-based overflow leading to denial-of-service Package: poppler; Maintainer for poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Antoine Beaupre <anarcat@orangeseedsorg> Date: Thu, 6 Jul 2017 1 ...
Debian Bug report logs - #865680 poppler: CVE-2017-9775: stack buffer overflow in GfxStatecc Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Jun 2017 17:27: ...
Debian Bug report logs - #864009 poppler: CVE-2017-9408: memory leak in Object::initArray Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Jun 2017 03:09:01 U ...
Debian Bug report logs - #864010 poppler: CVE-2017-9406: memory leak parsing XRef entries Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Jun 2017 03:15:02 U ...