On Sat, May 20, 2017 at 10:30:17AM +0200, Salvatore Bonaccorso wrote:
> the following vulnerability was published for poppler.
> 
> CVE-2017-9083[0]:
> | poppler 0.54.0, as used in Evince and other products, has a NULL
> | pointer dereference in the JPXStream::readUByte function in
> | JPXStream.cc. For example, the perf_test utility will crash
> | (segmentation fault) when parsing an invalid PDF file.

Does this apply to Debian's poppler?  I think uses openjpeg instead of
the internal JPX decoder.

There's a discussion on the poppler mailing list about making it more
explicit that the internal decoders are unmaintained:
https://lists.freedesktop.org/archives/poppler/2017-May/012230.html

Reply via email to