CVE-2017-14977 PUBLISHED

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

EPSS 1.10% · 77.9th percentile

Risk Scores

EPSS Score
1.10%
77.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpoppler0, 0.33.0-0ubuntu3, 0.37.0-0ubuntu1
Ubuntu:14.04:LTSpoppler0.24.3-0ubuntu7, 0.24.3-0ubuntu8, 0.24.3-0ubuntu10

Timeline

References

Open in Interactive Console →