Bug 1047949 - (CVE-2017-2820) VUL-0: CVE-2017-2820: poppler: Poppler PDF library JPEG 2000 levels Code Execution Vulnerability
VUL-0: CVE-2017-2820: poppler: Poppler PDF library JPEG 2000 levels Code Exec...
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Peter Simons
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2017-07-10 12:34 UTC by Marcus Meissner
Modified: 2022-09-30 12:39 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
gianluca.gabrielli: needinfo? (meissner)
stoyan.manolov: needinfo? (peter.simons)


Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-07-10 12:34:16 UTC


An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.
Comment 13 Stoyan Manolov 2022-09-30 12:39:01 UTC
After careful consideration on our end, we have come to the decision that backporting this fix is not economically or timely feasible. Please reach out to security@suse.de in case of any questions.