ZeroHour

CVE-2017-2818

CVSS 3.0
8.8 high
EPSS
2%p79
Published
()
Modified
Description

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.

Vendors
freedesktop
Products
poppler
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news