CVE-2017-2820
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.42% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- freedesktop/poppler
- Source
- talos-cna@cisco.com
References
- http://www.securityfocus.com/bid/99497Broken Link, Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0321Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/99497Broken Link, Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0321Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.