Bugzilla – Bug 1047949
VUL-0: CVE-2017-2820: poppler: Poppler PDF library JPEG 2000 levels Code Execution Vulnerability
Last modified: 2022-09-30 12:39:01 UTC
CVE-2017-2820 https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0321 An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.
After careful consideration on our end, we have come to the decision that backporting this fix is not economically or timely feasible. Please reach out to security@suse.de in case of any questions.