4.3
CVSSv2

CVE-2017-9083

Published: 19/05/2017 Updated: 14/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop poppler 0.54.0

Vendor Advisories

Debian Bug report logs - #863016 poppler: CVE-2017-9083 Package: src:poppler; Maintainer for src:poppler is Debian freedesktoporg maintainers <pkg-freedesktop-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 20 May 2017 08:33:02 UTC Severity: minor Tags: fixed-up ...
poppler could be made to crash or run programs as your login if it opened a specially crafted file ...
poppler 0540, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStreamcc For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file ...