Security readout for executives and security teams
Plain-English summary
CVE-2017-14928 is a Poppler PDF parsing crash issue. A specially crafted PDF can trigger a NULL pointer dereference in Poppler 0.59.0, potentially interrupting applications or services that process PDFs. The sources do not show active exploitation or a complete affected-version range.
Executive priority
Address through normal vulnerability management, with higher priority for systems that automatically process external PDFs. Business risk is service disruption rather than confirmed data compromise based on available sources.
Technical view
The flaw is in AnnotRichMedia::Configuration::Configuration in Annot.cc. The reported trigger is a crafted PDF document causing NULL pointer dereference behavior. Available data does not provide CVSS, CWE, full package range, or exploit maturity details.
Likely exposure
Exposure is most likely where Poppler 0.59.0, or vulnerable downstream Poppler packages, process untrusted PDFs. Higher operational concern applies to automated document ingestion, PDF preview, email attachment handling, and server-side conversion workflows.
Exploitation context
The cited CVE states exploitation requires a crafted PDF. CISA KEV status is false in the bundle, and no cited source confirms active exploitation. Treat this primarily as denial-of-service risk unless vendor advisories state otherwise.
Researcher notes
Evidence is sparse: the bundle identifies Poppler 0.59.0, a NULL dereference location, and a crafted PDF trigger. It does not provide CVSS, CWE, full affected range, fixed upstream commit, or proof of active exploitation.
Mitigation direction
- Inventory systems and applications that use Poppler for PDF parsing.
- Apply vendor Poppler security updates, including relevant distro advisories.
- Prioritize services that process untrusted or internet-supplied PDFs.
- Limit automated processing of untrusted PDFs until affected packages are updated.
- Monitor upstream and distro advisories for exact fixed package versions.
Validation and detection
- Check installed Poppler package versions across endpoints and servers.
- Confirm whether distributions include the referenced Poppler security update.
- Review PDF-processing services for crash reports tied to malformed documents.
- Verify automated ingestion pipelines recover cleanly from parser failures.
- Document remaining systems where affected-version status is uncertain.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-14928 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://bugs.freedesktop.org/show_bug.cgi?id=102607CVE reference · x_refsource_CONFIRM
- [debian-lts-announce] 20201108 [SECURITY] [DLA 2440-1] poppler security updateCVE reference · mailing-list, x_refsource_MLIST
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
