CVE-2017-14517

Priority
Medium
Description
In Poppler 0.59.0, a NULL Pointer Dereference exists in the
XRef::parseEntry() function in XRef.cc via a crafted PDF document.
References
Bugs
Notes
 leosilva> couldn't reproduce in trusty or xenial using POC
Assigned-to
leosilva
Package
Upstream:needs-triage
Ubuntu 17.10 (Artful Aardvark):released (0.57.0-2ubuntu2)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):not-affected (not reproducible)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (not reproducible)
Ubuntu 17.04 (Zesty Zapus):released (0.48.0-2ubuntu2.2)
Patches:
Upstream:https://cgit.freedesktop.org/poppler/poppler/commit/?id=476394e7a025e02e4897da2e765df2c895d0708f
More Information

Updated: 2017-10-10 16:14:38 UTC (commit 13484)