Bug 1047950 - (CVE-2017-2818) VUL-0: CVE-2017-2818: poppler: Poppler PDF Image Display DCTStream::readProgressiveSOF() Code ExecutionVulnerability
(CVE-2017-2818)
VUL-0: CVE-2017-2818: poppler: Poppler PDF Image Display DCTStream::readProgr...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Normal
: ---
Assigned To: Peter Simons
Security Team bot
https://smash.suse.de/issue/188173/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-07-10 12:42 UTC by Marcus Meissner
Modified: 2017-07-10 12:51 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-07-10 12:42:52 UTC
CVE-2017-2818

https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0319

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler-0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.
Comment 1 Marcus Meissner 2017-07-10 12:51:21 UTC
as we build all popplers with libjpeg we are not affected by this problem in the poppler internal jpeg decoding code.