CVE Vulnerabilities

CVE-2017-7515

Uncontrolled Recursion

Published: Jun 06, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
PopplerFreedesktop*0.55.0 (including)
PopplerUbuntudevel*
PopplerUbuntuesm-infra/xenial*
PopplerUbuntutrusty*
PopplerUbuntuvivid/stable-phone-overlay*
PopplerUbuntuxenial*
PopplerUbuntuyakkety*
PopplerUbuntuzesty*

Potential Mitigations

References