Medium severity5.5NVD Advisory· Published Jun 25, 2017· Updated May 13, 2026
CVE-2017-9865
CVE-2017-9865
Description
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.
Affected products
3- cpe:2.3:a:freedesktop:poppler:0.54.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- somevulnsofadlab.blogspot.com/2017/06/popplerstack-buffer-overflow-in.htmlnvdThird Party Advisory
- bugs.freedesktop.org/show_bug.cginvdIssue TrackingVendor Advisory
- security.gentoo.org/glsa/201801-17nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4079nvdThird Party Advisory
- usn.ubuntu.com/4042-1/nvd
News mentions
0No linked articles in our index yet.