CVE Vulnerabilities

CVE-2017-7515

Uncontrolled Recursion

Published: Jun 06, 2017 | Modified: Oct 09, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
NEGLIGIBLE

poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

Name Vendor Start Version End Version
Poppler Freedesktop * 0.55.0 (including)
Poppler Ubuntu devel *
Poppler Ubuntu trusty *
Poppler Ubuntu vivid/stable-phone-overlay *
Poppler Ubuntu xenial *
Poppler Ubuntu yakkety *
Poppler Ubuntu zesty *

Potential Mitigations

References