CVE-2017-9865 PUBLISHED

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.

EPSS 0.76% · 73.2th percentile

Risk Scores

EPSS Score
0.76%
73.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpoppler0, 0.33.0-0ubuntu3, 0.37.0-0ubuntu1

Timeline

References

Open in Interactive Console →