Vulnerability Description
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freedesktop | Poppler | 0.53.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99497Broken LinkThird Party AdvisoryVDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0321ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/99497Broken LinkThird Party AdvisoryVDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0321ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-2820?
CVE-2017-2820 is a vulnerability with a CVSS score of 8.8 (HIGH). An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causin...
How severe is CVE-2017-2820?
CVE-2017-2820 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2820?
Check the references section above for vendor advisories and patch information. Affected products include: Freedesktop Poppler.