Bug 1047950 - (CVE-2017-2818) VUL-0: CVE-2017-2818: poppler: Poppler PDF Image Display DCTStream::readProgressiveSOF() Code ExecutionVulnerability
VUL-0: CVE-2017-2818: poppler: Poppler PDF Image Display DCTStream::readProgr...
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P5 - None : Normal
: ---
Assigned To: Peter Simons
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2017-07-10 12:42 UTC by Marcus Meissner
Modified: 2017-07-10 12:51 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-07-10 12:42:52 UTC


An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler-0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.
Comment 1 Marcus Meissner 2017-07-10 12:51:21 UTC
as we build all popplers with libjpeg we are not affected by this problem in the poppler internal jpeg decoding code.