CVE Vulnerabilities

CVE-2017-7511

NULL Pointer Dereference

Published: May 30, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
PopplerFreedesktop0.17.3 (including)0.17.3 (including)
PopplerFreedesktop0.17.4 (including)0.17.4 (including)
PopplerFreedesktop0.18.0 (including)0.18.0 (including)
PopplerFreedesktop0.18.1 (including)0.18.1 (including)
PopplerFreedesktop0.18.2 (including)0.18.2 (including)
PopplerFreedesktop0.18.3 (including)0.18.3 (including)
PopplerFreedesktop0.18.4 (including)0.18.4 (including)
PopplerFreedesktop0.19.0 (including)0.19.0 (including)
PopplerFreedesktop0.19.1 (including)0.19.1 (including)
PopplerFreedesktop0.19.2 (including)0.19.2 (including)
PopplerFreedesktop0.19.3 (including)0.19.3 (including)
PopplerFreedesktop0.19.4 (including)0.19.4 (including)
PopplerFreedesktop0.20.0 (including)0.20.0 (including)
PopplerFreedesktop0.20.1 (including)0.20.1 (including)
PopplerFreedesktop0.20.2 (including)0.20.2 (including)
PopplerFreedesktop0.20.3 (including)0.20.3 (including)
PopplerFreedesktop0.20.4 (including)0.20.4 (including)
PopplerFreedesktop0.20.5 (including)0.20.5 (including)
PopplerFreedesktop0.21.0 (including)0.21.0 (including)
PopplerFreedesktop0.21.1 (including)0.21.1 (including)
PopplerFreedesktop0.21.2 (including)0.21.2 (including)
PopplerFreedesktop0.21.3 (including)0.21.3 (including)
PopplerFreedesktop0.21.4 (including)0.21.4 (including)
PopplerFreedesktop0.22.0 (including)0.22.0 (including)
PopplerFreedesktop0.22.1 (including)0.22.1 (including)
PopplerFreedesktop0.22.2 (including)0.22.2 (including)
PopplerFreedesktop0.22.3 (including)0.22.3 (including)
PopplerFreedesktop0.22.4 (including)0.22.4 (including)
PopplerFreedesktop0.22.5 (including)0.22.5 (including)
PopplerFreedesktop0.23.0 (including)0.23.0 (including)
PopplerFreedesktop0.23.1 (including)0.23.1 (including)
PopplerFreedesktop0.23.2 (including)0.23.2 (including)
PopplerFreedesktop0.23.3 (including)0.23.3 (including)
PopplerFreedesktop0.23.4 (including)0.23.4 (including)
PopplerFreedesktop0.24.0 (including)0.24.0 (including)
PopplerFreedesktop0.24.1 (including)0.24.1 (including)
PopplerFreedesktop0.24.2 (including)0.24.2 (including)
PopplerFreedesktop0.24.3 (including)0.24.3 (including)
PopplerFreedesktop0.24.4 (including)0.24.4 (including)
PopplerFreedesktop0.24.5 (including)0.24.5 (including)
PopplerFreedesktop0.25.0 (including)0.25.0 (including)
PopplerFreedesktop0.25.1 (including)0.25.1 (including)
PopplerFreedesktop0.25.2 (including)0.25.2 (including)
PopplerFreedesktop0.25.3 (including)0.25.3 (including)
PopplerFreedesktop0.26.0 (including)0.26.0 (including)
PopplerFreedesktop0.26.1 (including)0.26.1 (including)
PopplerFreedesktop0.26.2 (including)0.26.2 (including)
PopplerFreedesktop0.26.3 (including)0.26.3 (including)
PopplerFreedesktop0.26.4 (including)0.26.4 (including)
PopplerFreedesktop0.26.5 (including)0.26.5 (including)
PopplerFreedesktop0.28.0 (including)0.28.0 (including)
PopplerFreedesktop0.28.1 (including)0.28.1 (including)
PopplerFreedesktop0.29.0 (including)0.29.0 (including)
PopplerFreedesktop0.30.0 (including)0.30.0 (including)
PopplerFreedesktop0.31.0 (including)0.31.0 (including)
PopplerFreedesktop0.32.0 (including)0.32.0 (including)
PopplerFreedesktop0.33.0 (including)0.33.0 (including)
PopplerFreedesktop0.34.0 (including)0.34.0 (including)
PopplerFreedesktop0.35.0 (including)0.35.0 (including)
PopplerFreedesktop0.36.0 (including)0.36.0 (including)
PopplerFreedesktop0.37.0 (including)0.37.0 (including)
PopplerFreedesktop0.38.0 (including)0.38.0 (including)
PopplerFreedesktop0.39.0 (including)0.39.0 (including)
PopplerFreedesktop0.40.0 (including)0.40.0 (including)
PopplerFreedesktop0.41.0 (including)0.41.0 (including)
PopplerFreedesktop0.42.0 (including)0.42.0 (including)
PopplerFreedesktop0.43.0 (including)0.43.0 (including)
PopplerFreedesktop0.44.0 (including)0.44.0 (including)
PopplerFreedesktop0.45.0 (including)0.45.0 (including)
PopplerFreedesktop0.46.0 (including)0.46.0 (including)
PopplerFreedesktop0.47.0 (including)0.47.0 (including)
PopplerFreedesktop0.48.0 (including)0.48.0 (including)
PopplerFreedesktop0.49.0 (including)0.49.0 (including)
PopplerFreedesktop0.50.0 (including)0.50.0 (including)
PopplerFreedesktop0.51.0 (including)0.51.0 (including)
PopplerFreedesktop0.52.0 (including)0.52.0 (including)
PopplerFreedesktop0.53.0 (including)0.53.0 (including)
PopplerFreedesktop0.54.0 (including)0.54.0 (including)
PopplerFreedesktop0.55.0 (including)0.55.0 (including)
PopplerUbuntudevel*
PopplerUbuntuesm-infra/xenial*
PopplerUbuntutrusty*
PopplerUbuntuvivid/stable-phone-overlay*
PopplerUbuntuxenial*
PopplerUbuntuyakkety*
PopplerUbuntuzesty*

Potential Mitigations

References