The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Poppler | Freedesktop | 0.59.0 (including) | 0.59.0 (including) | 
| Poppler | Ubuntu | devel | * | 
| Poppler | Ubuntu | esm-infra/xenial | * | 
| Poppler | Ubuntu | trusty | * | 
| Poppler | Ubuntu | xenial | * | 
| Poppler | Ubuntu | zesty | * |