CVE-2017-2820 PUBLISHED

An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.

EPSS 1.69% · 82.1th percentile

Risk Scores

EPSS Score
1.69%
82.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpoppler0, 0.33.0-0ubuntu3, 0.37.0-0ubuntu1
Ubuntu:14.04:LTSpoppler0.24.3-0ubuntu5, 0.24.3-0ubuntu6, 0.24.3-0ubuntu7

Timeline

References

Open in Interactive Console →