GCVE-VVD-MAGEIA-2017-360
Advisory Published
Vulnetix · Advisory published October 5, 2017
In Poppler 0.59.0, a NULL Pointer Dereference exists in the
XRef::parseEntry() function in XRef.cc via a crafted PDF document.
(CVE-2017-14517)
In Poppler 0.59.0, memory corruption occurs in a call to
Object::streamGetChar in Object.h after a repeating series of
Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and
Gfx::doShowText calls (aka a Gfx.cc infinite loop). (CVE-2017-14519)
In Poppler 0.59.0, a floating point exception occurs in
Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential
attack when handling malicious PDF files. (CVE-2017-14520)