VDB
GCVE-VVD-MAGEIA-2017-378
GCVE-VVD-MAGEIA-2017-378
Advisory Published
In Poppler 0.59.0, a floating point exception exists in the
isImageInterpolationRequired() function in Splash.cc via a crafted PDF
document. (CVE-2017-14518)
In Poppler 0.59.0, a floating point exception occurs in the ImageStream
class in Stream.cc, which may lead to a potential attack when handling
malicious PDF files. (CVE-2017-14617)
In Poppler 0.59.0, a NULL Pointer Dereference exists in
AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.
(CVE-2017-14926)
In Poppler 0.59.0, a NULL Pointer Dereference exists in
AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted
PDF document. (CVE-2017-14928)
In Poppler 0.59.0, memory corruption occurs in a call to
Object::dictLookup() in Object.h after a repeating series of
Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill,
Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite
loop), a different vulnerability than CVE-2017-14519. (CVE-2017-14929)
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler
0.59.0 has a NULL pointer dereference vulnerability because a data
structure is not initialized, which allows an attacker to launch a
denial of service attack. (CVE-2017-14975)
The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler
0.59.0 has a NULL pointer dereference vulnerability due to lack of
validation of a table pointer, which allows an attacker to launch a
denial of service attack. (CVE-2017-14977)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | poppler | 0 (affected), 0.52.0-3.3.mga6 (unaffected) | — |
| Mageia | poppler | 0 (affected), 0.26.5-2.5.mga5 (unaffected) | — |
Aliases
Transitive aliases
EUVD-2017-6451SUSE-SU-2018:1662-1EUVD-2017-6405GSD-2017-14617GHSA-xx3m-8628-m9w5BDU:2021-03367GHSA-r2f3-mjhr-vxhrGHSA-rhh3-rx8x-hwmmGHSA-p32h-j7f8-3j6gBDU:2021-03366GSD-2017-14926GHSA-59jf-2fgh-pcgpGHSA-m66m-h4r9-wjp8EUVD-2017-6406SUSE-SU-2020:1626-1EUVD-2017-6118EUVD-2017-6403CNVD-2017-30080EUVD-2017-6019CNVD-2017-30077CNVD-2017-34098EUVD-2017-6453GSD-2017-14929GHSA-hjpq-cmqm-x5p7
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.