CVE-2017-1000456

Priority
Medium
Description
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in
TextPool::addWord, leading to overflow in subsequent calculations.
References
Bugs
Assigned-to
leosilva
Package
Upstream:released (0.61)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (0.24.5-2ubuntu4.9)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.41.0-0ubuntu1.6)
Ubuntu 17.10 (Artful Aardvark):released (0.57.0-2ubuntu4.2)
Ubuntu 18.04 LTS (Bionic Beaver):released (0.62.0-1ubuntu1)
Patches:
Upstream:https://cgit.freedesktop.org/poppler/poppler/commit/?id=7ee9dadef37b20bca707a6b1e858e17d191e368b
More Information

Updated: 2018-02-13 20:14:43 UTC (commit 14186)