NULL pointer derefenrece in Poppler - CVE-2017-14975
Published: October 2, 2017 / Updated: October 2, 2017
Poppler
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service (DoS) conditions.
The vulnerability exists due to an error in FoFiType1C::convertToType0 function in FoFiType1C.cc when processing documents. A remote attacker can send a specially crafted document, trigger NULL pointer dereference and perform a denial of service attack.
Successful exploitation of the vulnerability may allow an attacker to cause application crash.
How to mitigate CVE-2017-14975
https://bugzilla.freedesktop.org/show_bug.cgi?id=102653