Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-2818

Description

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.

POC

Reference

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0319

Github

- https://github.com/0xCyberY/CVE-T4PDF

- https://github.com/11notes/docker-paperless-ngx

- https://github.com/ARPSyndicate/cvemon