Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-2820
HistoryJul 07, 2017 - 12:00 a.m.

CVE-2017-2820

2017-07-0700:00:00
ubuntu.com
ubuntu.com
11

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

77.3%

An exploitable integer overflow vulnerability exists in the JPEG 2000 image
parsing functionality of freedesktop.org Poppler 0.53.0. A specially
crafted PDF file can lead to an integer overflow causing out of bounds
memory overwrite on the heap resulting in potential arbitrary code
execution. To trigger this vulnerability, a victim must open the malicious
PDF in an application using this library.

Notes

Author Note
mdeslaur contrary to Debian, Ubuntu uses the internal JPEG 2000 library as openjpeg has not been approved for main inclusion
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchpoppler< 0.24.5-2ubuntu4.5UNKNOWN
ubuntu16.04noarchpoppler< 0.41.0-0ubuntu1.2UNKNOWN
ubuntu16.10noarchpoppler< 0.44.0-3ubuntu2.1UNKNOWN
ubuntu17.04noarchpoppler< 0.48.0-2ubuntu2.1UNKNOWN

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

77.3%