CVE-2017-1000456

Priority
Medium
Description
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in
TextPool::addWord, leading to overflow in subsequent calculations.
References
Assigned-to
leosilva
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (0.24.5-2ubuntu4.9)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.41.0-0ubuntu1.6)
Ubuntu 17.04 (Zesty Zapus):released (0.48.0-2ubuntu2.5)
Ubuntu 17.10 (Artful Aardvark):released (0.57.0-2ubuntu4.2)
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
More Information

Updated: 2018-01-08 15:14:15 UTC (commit 13962)