Bug 1047949 - (CVE-2017-2820) VUL-0: CVE-2017-2820: poppler: Poppler PDF library JPEG 2000 levels Code Execution Vulnerability
(CVE-2017-2820)
VUL-0: CVE-2017-2820: poppler: Poppler PDF library JPEG 2000 levels Code Exec...
Status: RESOLVED WONTFIX
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Peter Simons
Security Team bot
https://smash.suse.de/issue/188171/
CVSSv2:SUSE:CVE-2017-2820:6.8:(AV:N/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-07-10 12:34 UTC by Marcus Meissner
Modified: 2022-09-30 12:39 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
gianluca.gabrielli: needinfo? (meissner)
stoyan.manolov: needinfo? (peter.simons)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-07-10 12:34:16 UTC
CVE-2017-2820

https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0321


An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.
Comment 13 Stoyan Manolov 2022-09-30 12:39:01 UTC
After careful consideration on our end, we have come to the decision that backporting this fix is not economically or timely feasible. Please reach out to security@suse.de in case of any questions.